""ET EXPLOIT Windows DNS Server RCE Attempt Inbound (CVE-2021-26897)""

SID: 2032348

Revision: 1

Class Type: attempted-admin

Metadata: attack_target DNS_Server, created_at 2021_03_30, cve CVE_2021_26897, deployment Perimeter, deployment Internal, signature_severity Major, updated_at 2021_03_30

Reference:

  • cve

  • 2021-26897

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $DNS_SERVERS

Destination Port: 53

Flow:

Contents:

  • Value: "|29 00|" Depth: 2 Offset: 2

Within:

PCRE:

Special Options:

source