Skip to content

clsid+rtfobj: add detection for CVE-2018-0798 #530

@decalage2

Description

@decalage2

See https://www.anomali.com/blog/multiple-chinese-threat-groups-exploiting-cve-2018-0798-equation-editor-vulnerability-since-late-2018
Check the samples exploiting CVE-2018-0798 and which CLSIDs/class names they use, update clsid and rtfobj accordingly.

Metadata

Metadata

Assignees

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions