
Rule Info
Av Ratio
1.62
Score
85
Name
EXPL_POC_VMWare_Workspace_ONE_CVE_2022_22954_Apr22
Minimum Yara
1.7
Required Modules
[]
Description
Detects payload as seen in PoC code to exploit Workspace ONE Access freemarker server-side template injection CVE-2022-22954
Modified
2022-04-12
Date
2022-04-08
Tags
['T1221', 'EXPLOIT', 'CVE_2022_22954', 'T1087']
Rule Hash
aba2c30d76f31b64bd629bc38d985082
Author
Florian Roth
Antivirus Verdicts
Rating
Number of Samples
Malicious (>= 10 engines)
1
Suspicious (< 10 engines)
15
Clean (0 engines)
23
Rule Matches
Positives
Hash
Total
Timestamp
VT