Video: Quick & Dirty Shellcode Analysis – CVE-2017-11882, (Sun, Feb 27th)

Xavier did a dynamic analysis of a malicious document with an equation editor exploit.

In this video, I perform a quick & dirty static analysis using, xorsearch and scdbg.

If you are more interested in all the technical details of an equation editor exploit, take a look at diary entry Dissecting a CVE-2017-11882 Exploit.


Didier Stevens
Senior handler
Microsoft MVP

(c) SANS Internet Storm Center. Creative Commons Attribution-Noncommercial 3.0 United States License.

Reposted from SANS. View original.