Internet Explorer 0 Day - Sept 17, 2012

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Internet Explorer 0 Day - Sept 17, 2012

L3 Networker

Is there a signature for the new IE 0 day yet?

There is a metasploit module out so.. that means there a working exploit 'in the wild' to base a sig on...

Normally I find the CVE and then look it up in Threat Vault which will give me the threats version number (eg: 839-1155) that I can confirm is installed on my FW.

However this time, I cant find a CVE number so Im asking here.

Thanks

18 REPLIES 18

update 330-1516 available now

Thanks, downloaded and installed just fine !

Hi everybody,

thanks for the update. Anyway, I've got a question: Why are there two threat-ids obviously covering the same vulnerability? How do they differ and how do I have to interpret the different default actions?

The background of my question is that I'm not really sure what will happen if the vulnerability protection profile is configured to apply the "default" action for all "critical" threats --> will it execute "reset-client" or only "alert" or both?

PS: Sorry for asking, I'm aware that maybe this is a (dumb) newbie question...

Good question...

My current guess is that both will fire since they have the same info:

https://threatvault.paloaltonetworks.com/Home/ThreatDetail/35017

https://threatvault.paloaltonetworks.com/Home/ThreatDetail/35018

so first it will reset-client and then it will log (alert)... but that sounds odd because if default action is reset-client then logging is included in that - isnt it?

Or if someone wants just to monitor/log if/when such packets are seen then they would set this manually to alert wouldnt they?

  • 6160 Views
  • 18 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!