I am getting an event type called "Windows ASN.1 Bit String NTLMv2 Integer Overflow" on my Cisco MARS server. I am not sure what it means even though the definition is given below:
This signature detects malformed ASN.1 data during Windows NTLMv2 authentication that may indicate an attempt to exploit an ASN.1 bit string integer overflow vulnerability in the Microsoft ASN.1 Library ("msasn1.dll") during ASN.1 BER decoding. Successful exploitation may allow execution of arbitrary code on an affected system with SYSTEM privileges. Services affected are Kerberos (UDP/8

and NTLMv2 authentication (TCP/135, 139, 445).
All of the events include our DNS server/ Domain Controller as the source/destination.
Anyone have any idea on how to troubleshoot this or check to see if this is just a false positive?
Thanks!