Execution of software vulnerable to webp buffer overflow of CVE-2023-4863

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query looks at device, process, and network events from Defender for Endpoint that may be vulnerable to buffer overflow defined in CVE-2023-4863. Results are not an indicator of malicious activity.

Attribute Value
Type Analytic Rule
Solution Microsoft Defender XDR
ID 26e81021-2de6-4442-a74a-a77885e96911
Severity Informational
Status Available
Kind Scheduled
Tactics Execution
Techniques T1203
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceEvents ?
DeviceNetworkEvents ?
DeviceProcessEvents ?
DeviceTvmSoftwareVulnerabilities ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Microsoft Defender XDR