Description
Detects contact card files exploiting the Windows contact parsing flaw documented in public research, which can allow code execution when the file opens. The rule matches the crafted card structures that drive the vulnerable parser paths.