cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Threat detections of "Canonical ksmbd-tools ksmbd.mountd ndrwritebytes Heap Buffer Overflow Vulnerability(94951)" in Windows server traffic

L1 Bithead

Anyone else seeing the following alerts:
tcp
,alert,"gpt.ini",Canonical ksmbd-tools ksmbd.mountd ndrwritebytes Heap Buffer Overflow Vulnerability(94951)

 

But this is being detected in traffic between 2 Windows server, so it doesn't make sense. Seems to be a false positive.

 

 

Who Me Too'd this topic