Microsoft Sentinel Analytic Rules
cloudbrothers.infoAzure Sentinel RepoToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeToggle Dark/Light/Auto modeBack to homepage

Execution of software vulnerable to webp buffer overflow of CVE-2023-4863

Back
Id26e81021-2de6-4442-a74a-a77885e96911
RulenameExecution of software vulnerable to webp buffer overflow of CVE-2023-4863
DescriptionThis query looks at device, process, and network events from Defender for Endpoint that may be vulnerable to buffer overflow defined in CVE-2023-4863. Results are not an indicator of malicious activity.
SeverityInformational
TacticsExecution
TechniquesT1203
Required data connectorsMicrosoftThreatProtection
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Defender XDR/Analytic Rules/PossibleWebpBufferOverflow.yaml
Version1.1.2
Arm template26e81021-2de6-4442-a74a-a77885e96911.json
Deploy To Azure
//CVE-2023-4863 Process activity with .webp files on devices where CVE-2023-4863 is unpatched
//This query shows all process activity with .webp files on vulnerable machines and is not an indicator of malicious activity
let VulnDevices = DeviceTvmSoftwareVulnerabilities
    | where CveId == "CVE-2023-4863"
    | distinct DeviceId;
union DeviceProcessEvents, DeviceNetworkEvents, DeviceEvents
| where DeviceId in (VulnDevices) and (InitiatingProcessCommandLine has(".webp") or ProcessCommandLine has(".webp"))
| extend Name = tostring(split(AccountUpn, "@")[0]), UPNSuffix = tostring(split(AccountUpn, "@")[1])
| extend HostName = tostring(split(DeviceName, ".")[0]), DomainIndex = toint(indexof(DeviceName, '.'))
| extend HostNameDomain = iff(DomainIndex != -1, substring(DeviceName, DomainIndex + 1), DeviceName)
description: |
    'This query looks at device, process, and network events from Defender for Endpoint that may be vulnerable to buffer overflow defined in CVE-2023-4863. Results are not an indicator of malicious activity.'
entityMappings:
- fieldMappings:
  - columnName: DeviceName
    identifier: FullName
  - columnName: HostName
    identifier: HostName
  - columnName: HostNameDomain
    identifier: DnsDomain
  entityType: Host
- fieldMappings:
  - columnName: AccountUpn
    identifier: FullName
  - columnName: Name
    identifier: Name
  - columnName: UPNSuffix
    identifier: UPNSuffix
  entityType: Account
- fieldMappings:
  - columnName: LocalIP
    identifier: Address
  entityType: IP
- fieldMappings:
  - columnName: ProcessId
    identifier: ProcessId
  entityType: Process
- fieldMappings:
  - columnName: InitiatingProcessId
    identifier: ProcessId
  entityType: Process
- fieldMappings:
  - columnName: ProcessCommandLine
    identifier: CommandLine
  entityType: Process
kind: Scheduled
tactics:
- Execution
severity: Informational
triggerThreshold: 0
queryFrequency: 1h
status: Available
queryPeriod: 1h
relevantTechniques:
- T1203
tags:
- CVE-2023-4863
id: 26e81021-2de6-4442-a74a-a77885e96911
name: Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
incidentConfiguration:
  createIncident: false
  groupingConfiguration:
    reopenClosedIncident: false
    groupByCustomDetails: []
    enabled: false
    matchingMethod: Selected
    groupByAlertDetails: []
    groupByEntities:
    - Account
    lookbackDuration: PT5H
query: |-
  //CVE-2023-4863 Process activity with .webp files on devices where CVE-2023-4863 is unpatched
  //This query shows all process activity with .webp files on vulnerable machines and is not an indicator of malicious activity
  let VulnDevices = DeviceTvmSoftwareVulnerabilities
      | where CveId == "CVE-2023-4863"
      | distinct DeviceId;
  union DeviceProcessEvents, DeviceNetworkEvents, DeviceEvents
  | where DeviceId in (VulnDevices) and (InitiatingProcessCommandLine has(".webp") or ProcessCommandLine has(".webp"))
  | extend Name = tostring(split(AccountUpn, "@")[0]), UPNSuffix = tostring(split(AccountUpn, "@")[1])
  | extend HostName = tostring(split(DeviceName, ".")[0]), DomainIndex = toint(indexof(DeviceName, '.'))
  | extend HostNameDomain = iff(DomainIndex != -1, substring(DeviceName, DomainIndex + 1), DeviceName)  
triggerOperator: gt
version: 1.1.2
suppressionEnabled: false
suppressionDuration: PT5H
eventGroupingSettings:
  aggregationKind: SingleAlert
alertDetailsOverride:
  alertDynamicProperties: []
  alertDisplayNameFormat: Possible exploitation of CVE-2023-4863
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft Defender XDR/Analytic Rules/PossibleWebpBufferOverflow.yaml
requiredDataConnectors:
- dataTypes:
  - DeviceProcessEvents
  - DeviceNetworkEvents
  - DeviceEvents
  - DeviceTvmSoftwareVulnerabilities
  connectorId: MicrosoftThreatProtection