Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jonas_Jacala
Explorer

We would like to find out what cause this signature “Microsoft Windows File Manager Remote Code Exec

We would like to find out what cause this signature “Microsoft Windows File Manager Remote Code Execution (MS16-130: CVE-2016-7212)” to trigger in Checkpoint IPS.

 

From the Checkpoint logs, it appears as inbound traffic.

But from the downloaded packet capture, it is reflected the other way round.

Which traffic is triggering this alert?

 

We have enabled HTTPS Inspection but seems like the packet capture is still encrypted.

Do let us know if we are still lacking of any information to aid in the investigation and we will try to provide.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

The initial TCP connection could have easily been the other way.
Hard to say without seeing the log card in question.

Regardless, this will probably require a TAC case to get more details.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events