cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1462
Views
0
Helpful
5
Replies

Anyone else notice IPS Signature 1548/0 firing frequently?

JonPBerbee
Level 1
Level 1

Hello.

We have seen IPS Signature 1548/0-"Microsoft Offic Picture Managed Memory Corruption" trigger frequently on image files downloaded from IP addresses associated with Microsoft, in the range of 207.46.0.0/16.  This has happened for several different customers we manage and I'm wondering if anyone else has seen this new signature fire frequently.

It looks to me that this signature has not been tuned correctly by Cisco because in every case the "Source" IP in the alert was from Microsoft.  Just wondering if anyone else has seen this too.

Jon.

5 Replies 5

ruppala
Level 1
Level 1

Jon,

       The IPS Signature team is researching into this issue and will update you as soon as we have more information.

-Roopesh

wgorman
Level 1
Level 1

yes, as soon as this signature was released by Cisco we have been seeing Microsoft (65.54.0.0/16) as the source of this activity.

-will

Yeah, we just had some fire in the 65.54.0.0/16 range in addition to the 207.46.0.0/16 range.

Thanks Roopesh for bringing this to the signature team for review, let us know what you find out.

ruppala
Level 1
Level 1

The signature will be disabled and retired in an upcoming signature update.  The new signature will have an updated benign triggers section to reflect that this sig may trigger on potentially benign traffic. In the meanwhile , please feel free to disable and retire this signature. Let me know if you have any additional questions.

Thanks for the update Roopesh.  We ended up just filting this out in the MARS appliances when the source addresses belonged to Microsoft.

Review Cisco Networking for a $25 gift card