Release notes for update package 1461-5242

This update package improves the detection capabilities of the Forcepoint LLM system.

RELEASE DATE:     Thursday May 05, 2022
MD5 CHECKSUM:     ab689ab3b1372e83f6a893c3444b36a4
SHA1 CHECKSUM:     43a29e795c4f3f1f1e1b5e164f7cb6f84e0bebea
SHA256 CHECKSUM:     426c7f5f0dbb860c832ab27f79540b4bf111fa96b0e90a3d9feaa92b94634158

UPDATE CRITICALITY:    HIGH

List of detected attacks in this update package:

Risk level Description Reference Vulnerability
High     An attempt to exploit a vulnerability in Microsoft Windows detected     CVE-2022-21907     HTTP_Protocol_Stack_Remote_Code_Execution_Vulnerability_CVE-2022-21907
High     An attempt to exploit a vulnerability in ManageEngine ADSelfService Plus detected.     CVE-2022-28810     Manageengine-Adselfservice-Plus-Custom-Script-Execution

Jump to: Detected Attacks

DETECTED ATTACKS

New detected attacks:

HTTP Client Stream

Risk Vulnerability/Situation References Related Fingerprint Situation Type
High HTTP_Protocol_Stack_Remote_Code_Execution_Vulnerability_CVE-2022-21907 CVE-2022-21907 HTTP_CS-HTTP_Protocol_Stack_Remote_Code_Execution_Vulnerability_CVE-2022-21907 Suspected Compromise
High Manageengine-Adselfservice-Plus-Custom-Script-Execution CVE-2022-28810 HTTP_CS-Manageengine-Adselfservice-Plus-Custom-Script-Execution Suspected Compromise

Updated detected attacks:

TCP Client Stream Unknown

Risk Vulnerability/Situation References Related Fingerprint Situation Type Change Description
High Redis-Lua-Sandbox-Escape-CVE-2022-0543 CVE-2022-0543 Generic_CS-Redis-Lua-Sandbox-Escape-CVE-2022-0543 Suspected Compromise
Fingerprint regexp changed

DISCLAIMER AND COPYRIGHT

Copyright © 2022 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.