""ET WEB_CLIENT Type Confusion Microsoft Edge (CVE-2017-11873)""

SID: 2024993

Revision: 2

Class Type: attempted-user

Metadata: affected_product Web_Browsers, attack_target Client_Endpoint, created_at 2017_11_15, cve CVE_2017_11873, deployment Perimeter, performance_impact Significant, signature_severity Major, updated_at 2017_11_15

Reference:

  • cve

  • 2017-11873

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "[1.1, 2.2"

  • Value: "Array(100)"

  • Value: "i = 0|3b| i < 100"

  • Value: "function opt("

Within:

PCRE: "/^(?:]|, 3.3])\x3b/R"

Special Options:

  • file_data

  • fast_pattern

source