Signature Base unknown stable yara
SUSP_EXPL_Msg_CVE_2023_23397_Mar23 [yara]
MSG file with a PidLidReminderFileParameter property, potentially exploiting CVE-2023-23397
Detection Logic
uint32be(0) == 0xD0CF11E0
and uint32be(4) == 0xA1B11AE1
and 1 of ($psetid*)
and $rfp
and $u1
and not 1 of ($fp*) Field Validations
Loading…
Comments (0)
Loading comments...