Netskope Threat Labs

FILE-OTHER Power Software PowerISO invalid primary volume descriptor header use after free attempt

IPS-SWG

1 SID: 42321

First seen
January 2024
Last seen
October 2026

Detects a disc image exploiting CVE-2017-2823, a use-after-free in PowerISO's volume descriptor parsing that can allow code execution. The rule matches the crafted image headers that public exploits use to free parser objects while they remain in use.