SUSP_EXPL_CommVault_CVE_2025_57791_Aug25_1
Description
Detects potential exploit for WT-2025-0050, authentication bypass through QCommand argument injection
Query · yara
strings:
$sa1 = "_localadmin__"
$sa2 = "-localadmin"
condition:
not uint16(0) == 0x5a4d and
filesize < 20MB and all of them