From d33da0b25cba9fe6da53c148b5eb3fd4533f9db8 Mon Sep 17 00:00:00 2001 From: Sittikorn S <61369934+BlackB0lt@users.noreply.github.com> Date: Fri, 2 Jul 2021 14:42:04 +0700 Subject: [PATCH] Update av_printernightmare_cve_2021_34527.yml --- rules/windows/malware/av_printernightmare_cve_2021_34527.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/rules/windows/malware/av_printernightmare_cve_2021_34527.yml b/rules/windows/malware/av_printernightmare_cve_2021_34527.yml index b3294ae94..10be4d39d 100644 --- a/rules/windows/malware/av_printernightmare_cve_2021_34527.yml +++ b/rules/windows/malware/av_printernightmare_cve_2021_34527.yml @@ -1,9 +1,10 @@ title: Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection id: 6fe1719e-ecdf-4caf-bffe-4f501cb0a561 status: stable -description: Detects the suspicius file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare). +description: Detects the suspicius file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare), CVE-2021-1675 . references: - https://twitter.com/mvelazco/status/1410291741241102338 + - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1675 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527 author: Sittikorn S, Nuttakorn T date: 2021/07/01