Description
Detects content exploiting CVE-2025-30388, a remote code execution flaw in the Windows graphics component that saw active exploitation. The rule matches the crafted metafile structures that the exploit uses to corrupt memory during rendering.