-
-
Notifications
You must be signed in to change notification settings - Fork 256
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Avoid detection of RTF as CVE-2017-0199 #23
Comments
What product is showing the alert? |
Trend micro antivirus and Avast. Also gmail and other mail scanners. |
Hey, AV evasion is explicitly not provided as part of this repo (and hard to maintain since it is open source). I'll keep this issue open for discussion though. |
Thank you for keeping it open. It is currently being incorrectly detected as a different CVE. |
From what I saw oletools detects this as possible CVE-2017-0199. I guess since it detects the URLMoniker and the OLE2Link class name with the RTF. |
The RTF files are being detected as CVE-2017-0199, any pointers or ideas on what we could do to avoid the rtf file being detected as CVE-2017-0199?
The text was updated successfully, but these errors were encountered: