lockedbyte / CVE-2021-40444

CVE-2021-40444 PoC
1.58k stars 483 forks source link

question #6

Open d3sh1n opened 3 years ago

d3sh1n commented 3 years ago

Hi, I have a question about the generation of the cab,why add this content to the cab file. image I want to add a vbs to the cab, do I need to modify the content of this place?

vest12385 commented 3 years ago

According to https://github.com/klezVirus/CVE-2021-40444, the field means CFFILE.cbFile (although it do not align perfectly), this field must large than CFHEADER.cbCabinet