SHELLCODE: Decoder Loop 1 (HTTP-STC)

This signature detects a known malicious shellcode decoder over the HTTP protocol. Decoders are used to hide malicious shellcode from detection.

Extended Description

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008. NOTE: As of 20081210, it is unclear whether this vulnerability is related to a WordPad issue disclosed on 20080925 with a 2008-crash.doc.rar example, but there are insufficient details to be sure.

References

BugTraq: 32718

CVE: CVE-2008-4841

Short Name
SHELLCODE:ACTIVE:DECODER1-80-SV
Severity
Critical
Recommended
False
Recommended Action
None
Category
SHELLCODE
Keywords
(HTTP-STC) 1 CVE-2008-4841 Decoder Loop bid:32718
Release Date
09/30/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown

Found a potential security threat?