Skip to main content
FSM_FTNT
Staff
Staff
February 11, 2022

Technical Tip: Using FortiSIEM to detect attempts at exploiting a Remote Code Execution vulnerability in Microsoft HTTP protocol stack

  • February 11, 2022
  • 0 replies
  • 703 views
Description

This article describes how to use custom Rules and Reports to raise alerts for incident response related to attacks that attempt to exploit a remote code execution vulnerability in the Microsoft HTTP protocol stack.

 

The vulnerability is due to an improper boundary check condition in the protocol when handling a crafted HTTP request.

 

A remote attacker may be able to exploit this to execute arbitrary code within the context of the application, via a crafted HTTP request.


This vulnerability is assigned CVE-2022-21907.

For more information about this attack, see the following FortiGuard Outbreak Alert.

 

FortiGuard Outbreak Alert - WinHTTP Protocol Stack RCE

Scope

What is included in Fortinet_FortiSIEM_HTTP_RCE_v1.zip?


1) FortiSIEM_RCE_Rules_v1.xml

This Rules help identify attacks which attempt to exploit a remote code execution vulnerability in Microsoft HTTP protocol stack detected by FortiGate, FortiClient and FortiSandbox logs.

 

2) FortiSIEM_RCE_Report_v1.xml

This report displays the findings on the HTTP protocol stack RCE outbreak from FortiGate, FortiClient and FortiSandbox logs.

Solution

1) Download the Fortinet_FortiSIEM_HTTP_RCE_v1.zip(contains 2 file).

 

2) Unzip Fortinet_FortiSIEM_HTTP_RCE_v1.zip

 

3) Use FortiSIEM_RCE_Reports_v1.xml as the file to import the Reports
- Navigate to Resource / Reports.
- It is recommended to create a new group under Resource / Reports / Security called 'HTTP RCE' and import reports to this group.
- Select the Import option under More.
- Select FortiSIEM_RCE_Rules_v1.xml and import.

 

4) Use FortiSIEM_RCE_Rules_v1.xml as the file to import the Rules
- Navigate to Resource / Rules.
- It is recommended to create a new group under Resource / Rules / Security / Threat Hunting is created called 'HTTP RCE' and import the rules to this group.
- Select the Import.
- Select FortiSIEM_RCE_Rules_v1.xml and import.
- Filter the rules for those defined in content pack 101 and ensure there are enabled.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.