Hello all, My customers PA-3020 detected a few Microsoft Vulnerability Threat coming from Inside ( Web server ) to Outside ( Internet ) . We investigated the cause of this , but could not replicate the issue and finding the cause of it. We scanned web server for malware , corrupt jpeg files but it was clean. Detected Vulnerabilities are : Microsoft Windows Paint JPEG Integer Overflow Vulnerability(32831) Microsoft DirectShow JPEG Parsing Memory Corruption Vulnerability(36396) Microsoft Windows Paint JPEG Integer Overflow Vulnerability(32831) PA-3020 log details: actionflags: 0x0 type: THREAT subtype: vulnerability config_ver: 1 time_generated: 2015/02/27 08:10:38 flags: 0x400000 proto: tcp action: alert cpadding: 0 threatid: Microsoft Windows Paint JPEG Integer Overflow Vulnerability(32831) category: any contenttype: behavior: 0x0500000000000000000000000000000000000000000000000000000000000000 severity: critical direction: server-to-client actionflags: 0x0 type: THREAT subtype: vulnerability config_ver: 1 proto: tcp action: alert cpadding: 0 threatid: Microsoft DirectShow JPEG Parsing Memory Corruption Vulnerability(36396) category: any contenttype: behavior: 0x0500000000000000000000000000000000000000000000000000000000000000 severity: critica l direction: server-to-client misc: Could this be a false positive from PA-3020 ? Has someone seen a similar alert on their Palo Alto firewall ? Thank you . Adrian
... View more