Commit 1522a114f6389670a0945addd897b15bbb7b150f

Authored by decalage2
1 parent f4c960c1

clsid: added Virtual Disk Service Loader - vdsldr.exe (related to MS Office clic…

…k-to-run issue CVE-2021-27058)
Showing 1 changed file with 1 additions and 0 deletions
oletools/common/clsid.py
... ... @@ -157,6 +157,7 @@ KNOWN_CLSIDS = {
157 157 '975797FC-4E2A-11D0-B702-00C04FD8DBF7': 'Loads ELSEXT.DLL (Known Related to CVE-2015-6128)',
158 158 '978C9E23-D4B0-11CE-BF2D-00AA003F40D0': 'Microsoft Forms 2.0 Label (Forms.Label.1)',
159 159 '996BF5E0-8044-4650-ADEB-0B013914E99C': 'MSCOMCTL.ListViewCtrl (may trigger CVE-2012-0158)',
  160 + '9C38ED61-D565-4728-AEEE-C80952F0ECDE': 'Virtual Disk Service Loader - vdsldr.exe (related to MS Office click-to-run issue CVE-2021-27058)',
160 161 'A08A033D-1A75-4AB6-A166-EAD02F547959': 'otkloadr WRAssembly Object (can be used to bypass ASLR after triggering an exploit)',
161 162 'B54F3741-5B07-11CF-A4B0-00AA004A55E8': 'vbscript.dll - VB Script Language (ProgID: VBS, VBScript)',
162 163 'B801CA65-A1FC-11D0-85AD-444553540000': 'Adobe Acrobat Document - PDF file',
... ...