Stats
- First seen
- January 2024
- Last seen
- October 2026
Description
Detects a disc image exploiting CVE-2017-2823, a use-after-free in PowerISO's volume descriptor parsing that can allow code execution. The rule matches the crafted image headers that public exploits use to free parser objects while they remain in use.









