decalage2 / oletools

oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging.
http://www.decalage.info/python/oletools
Other
2.81k stars 560 forks source link

Detect CVE-2023-36884 #821

Open yoshimo opened 11 months ago

yoshimo commented 11 months ago

Is your feature request related to a problem? Please describe. CVE-2023-36884 seems to be a RCE opportunity in office files

Describe the solution you'd like Find the documents that exploit this vulnerability

Describe alternatives you've considered Blocking all office documents.

decalage2 commented 9 months ago

Resources to be checked:

Samples: