Executive brief
Cisco's Snort 3 intrusion detection engine contains flaws in how it handles Visual Basic for Applications (VBA) macro decompression, which is used to inspect email and web traffic for malicious content. An attacker can craft malicious VBA data that causes the detection engine to crash unexpectedly, disrupting security monitoring and creating a temporary window of vulnerability.
Technical details
The vulnerability exists in the Snort 3 VBA decompression feature due to improper error checking when decompressing VBA data (CWE-122, CWE-369, CWE-786, CWE-835). An unauthenticated, remote attacker can send crafted VBA payloads to a device running vulnerable Snort 3 detection engine via network protocols that support VBA inspection (IMAP, SMTP, HTTP, POP3). The attack requires Snort 3 to be active and at least one Snort 3 Detector configured for VBA macro decompression (a non-default feature). Successful exploitation causes the Snort 3 Detection Engine to crash, resulting in a denial of service condition and loss of intrusion detection capabilities until the engine restarts.
Affected products
- Cisco Snort 3 Vulnerable releases as documented in Fixed Software section of advisory
- Cisco Secure Firewall Threat Defense (FTD) 7.2.0 and later (with Snort 3 and VBA decompression configured)
- Cisco IOS XE Releases with vulnerable UTD Snort IPS Engine
- Cisco Secure Firewall Management Center (FMC) Vulnerable releases as per March 2026 advisory
Timeline
- 2026-03-04: disclosed