TippingPoint Threat Intelligence and Zero-Day Coverage – Week of November 20, 2017

Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Wed, 22 Nov 2017 14:10:15 +0000

It’s that time of year again, when many will gather with their families, eat way too much, and catch those crazy Black Friday sales. I’ve been seeing “Black Friday” sales for almost two weeks now. Cyber Monday, which falls on the Monday after the U.S. Thanksgiving holiday, is probably going to be coupled with news of increased identity theft incidents.

I’ve said it before and I’ll say it again: if you choose to skip Black Friday and wait for Cyber Monday, be on the lookout for great deals you learn about via email or social media (don’t click the links!). Don’t use free public Wi-Fi to make purchases; and make sure sites you visit are secure (HTTPS) and have a valid encryption certificate. If you’re using your mobile phone, make sure you download apps from official app marketplaces or use a retailer’s actual URL. I hope you all have a safe and Happy Thanksgiving!

Adobe Security Update

This week’s Digital Vaccine® (DV) package includes coverage for Adobe updates released on or before November 14, 2017. The following table maps Digital Vaccine filters to the Adobe updates. Filters marked with an asterisk (*) shipped prior to this DV package, providing preemptive zero-day protection for customers. You can get more detailed information on this month’s security updates from Dustin Childs’ November 2017 Security Update Review from the Zero Day Initiative:

Bulletin #CVE #Digital Vaccine Filter #Status
APSB17-36CVE-2017-1636029994
APSB17-36CVE-2017-1636129999
APSB17-36CVE-2017-1636230030
APSB17-36CVE-2017-1636330023
APSB17-36CVE-2017-1636430006
APSB17-36CVE-2017-1636530027
APSB17-36CVE-2017-1636630019
APSB17-36CVE-2017-1636730014
APSB17-36CVE-2017-1636830015
APSB17-36CVE-2017-16369*28924
APSB17-36CVE-2017-1637029996
APSB17-36CVE-2017-1637130001
APSB17-36CVE-2017-1637230004
APSB17-36CVE-2017-1637330039
APSB17-36CVE-2017-1637430044
APSB17-36CVE-2017-1637530043
APSB17-36CVE-2017-16376Vendor Deemed Reproducibility or Exploitation Unlikely
APSB17-36CVE-2017-16377Vendor Deemed Reproducibility or Exploitation Unlikely
APSB17-36CVE-2017-16378Vendor Deemed Reproducibility or Exploitation Unlikely
APSB17-36CVE-2017-16379Vendor Deemed Reproducibility or Exploitation Unlikely
APSB17-36CVE-2017-16380Vendor Deemed Reproducibility or Exploitation Unlikely
APSB17-36CVE-2017-16381*29639
APSB17-36CVE-2017-16382*29638
APSB17-36CVE-2017-16383*29637
APSB17-36CVE-2017-16384*29636
APSB17-36CVE-2017-16385*29635
APSB17-36CVE-2017-16386*29584
APSB17-36CVE-2017-16387*29484
APSB17-36CVE-2017-1638830040
APSB17-36CVE-2017-1638930041
APSB17-36CVE-2017-1639029998
APSB17-36CVE-2017-1639130003
APSB17-36CVE-2017-1639230002
APSB17-36CVE-2017-1639330005
APSB17-36CVE-2017-1639430035
APSB17-36CVE-2017-1639530037
APSB17-36CVE-2017-1639630032
APSB17-36CVE-2017-1639730000
APSB17-36CVE-2017-1639829995
APSB17-36CVE-2017-1639929997
APSB17-36CVE-2017-16400*29852
APSB17-36CVE-2017-16401*29851
APSB17-36CVE-2017-16402*29853
APSB17-36CVE-2017-16403*29833
APSB17-36CVE-2017-16404*29850
APSB17-36CVE-2017-1640530038
APSB17-36CVE-2017-1640630042
APSB17-36CVE-2017-1640730045
APSB17-36CVE-2017-1640830034
APSB17-36CVE-2017-1640930036
APSB17-36CVE-2017-1641030024
APSB17-36CVE-2017-1641130021
APSB17-36CVE-2017-1641230020
APSB17-36CVE-2017-1641330018
APSB17-36CVE-2017-1641430016
APSB17-36CVE-2017-1641530025
APSB17-36CVE-2017-1641630007
APSB17-36CVE-2017-1641730013
APSB17-36CVE-2017-1641830017
APSB17-36CVE-2017-1641930022
APSB17-36CVE-2017-1642030026
APSB17-36CVE-2017-11293Vendor Deemed Reproducibility or Exploitation Unlikely
APSB17-33CVE-2017-311230008
APSB17-33CVE-2017-311430009
APSB17-33CVE-2017-1121330010
APSB17-33CVE-2017-1121530011
APSB17-33CVE-2017-1122530012

 

Zero-Day Filters

There are no new zero-day filters in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website. You can also follow the Zero Day Initiative on Twitter @thezdi and on their blog.

Missed Last Week’s News?

Catch up on last week’s news in my weekly recap.

http://feeds.trendmicro.com/TrendMicroSimplySecurity