Stats
- First seen
- October 2022
- Last seen
- August 2026
Description
Detects a document exploiting CVE-2017-11227, CVE-2017-11245, and CVE-2018-15946, memory access flaws in Adobe Acrobat's metafile comment handling that can leak memory or allow code execution. The rule matches the malformed comment records that public exploits use to reach vulnerable parser paths.