SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.
SERVER-OTHER Microsoft .NET FtpWebRequest CRLF injection attempt
This rule looks for a "RETR" command at the start of an FTP request and a second command appearing after a CRLF sequence within the same packet. Successful exploitation allows an attacker to bypass file permissions and gain elevated access on the FTP server.
This rule fires on attempts to exploit an escalation of privilege vulnerability in Microsoft .NET Framework FTP servers.
Public information/Proof of Concept available
Known false positives, with the described conditions
This rule may alert on benign FTP requests containing RETR and DELE commands in the same packet.
Cisco Talos Intelligence Group
Rule Categories::Server::Other
MITRE::ATT&CK Framework::Enterprise::Privilege Escalation::Exploitation for Privilege Escalation
Rule Categories::Protocol::FTP
Vulnerability::Severity::Critical
Vulnerability::Severity::High
Vendors + Products::Microsoft::.NET
Vendors + Products::Microsoft::Visual Studio
Escalation of Privilege
An Escalation of Privilege (EOP) attack is any attack method that results in a user or application gaining permissions to access resources they normally would not have access to.
CVE-2023-36049 |
Loading description
|