Signature Base unknown stable yara

SUSP_EXPL_Msg_CVE_2023_23397_Mar23 [yara]

MSG file with a PidLidReminderFileParameter property, potentially exploiting CVE-2023-23397

View Source

Detection Logic

uint32be(0) == 0xD0CF11E0
      and uint32be(4) == 0xA1B11AE1
      and 1 of ($psetid*)
      and $rfp
      and $u1
      and not 1 of ($fp*)

Field Validations

Loading…

Comments (0)

Loading comments...