Technical Tip: Using FortiSIEM to detect attempts at exploiting a Remote Code Execution vulnerability in Microsoft HTTP protocol stack
- February 11, 2022
- 0 replies
- 703 views
| Description | This article describes how to use custom Rules and Reports to raise alerts for incident response related to attacks that attempt to exploit a remote code execution vulnerability in the Microsoft HTTP protocol stack.
The vulnerability is due to an improper boundary check condition in the protocol when handling a crafted HTTP request.
A remote attacker may be able to exploit this to execute arbitrary code within the context of the application, via a crafted HTTP request.
For more information about this attack, see the following FortiGuard Outbreak Alert.
|
| Scope | What is included in Fortinet_FortiSIEM_HTTP_RCE_v1.zip?
This Rules help identify attacks which attempt to exploit a remote code execution vulnerability in Microsoft HTTP protocol stack detected by FortiGate, FortiClient and FortiSandbox logs.
2) FortiSIEM_RCE_Report_v1.xml This report displays the findings on the HTTP protocol stack RCE outbreak from FortiGate, FortiClient and FortiSandbox logs. |
| Solution | 1) Download the Fortinet_FortiSIEM_HTTP_RCE_v1.zip(contains 2 file).
2) Unzip Fortinet_FortiSIEM_HTTP_RCE_v1.zip
3) Use FortiSIEM_RCE_Reports_v1.xml as the file to import the Reports
4) Use FortiSIEM_RCE_Rules_v1.xml as the file to import the Rules |
