Description
Detects a PDF exploiting CVE-2021-28635, a use-after-free in Adobe Acrobat's form field handling that can allow code execution. The rule matches the scripted field additions that public exploits use to free form objects while they remain in use.