SUSP_EXPL_CommVault_CVE_2025_57791_Aug25_2
Description
Detects potential exploit for WT-2025-0050, authentication bypass through QCommand argument injection
Query · yara
strings:
$sa1 = "_localadmin__"
$sa2 = "-localadmin" base64
condition:
filesize < 20MB and all of them