Stats
- First seen
- January 2022
- Last seen
- October 2026
Description
Detects web content that exploits CVE-2017-0064 and CVE-2017-0066, security feature bypasses in Microsoft's CSS and script engine handling that can leak cross-origin data. The rule matches the browser property probes and launch URI calls that public exploits use to confirm the bypass before exfiltrating information.