I'm a little disappointed that this is not covered by the IPS, at least it's not in the rules list. Maybe this can't be handled by snort, I don't know.
Some information:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8581
and some in german:
https://www.frankysweb.de/active-directory-und-exchange-server-ueber-ews-api-angreifbar/
Please be aware of this.
Best regards
Alex
P.S. The rules are here: https://lists.astaro.com/ASGV9-IPS-rules.html#221
This thread was automatically locked due to age.