POLICY-OTHER --
POLICY-OTHER Microsoft Windows API MapUrlToZone potential security feature bypass attempt
This rule looks for a string within a file that is known to bypass a security feature in the Microsoft Windows API, MapUrlToZone.
This rule fires on potential attempts to bypass a security feature in the Microsoft Windows API, MapUrlToZone.
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE::ATT&CK Framework::Enterprise::Execution::User Execution::Malicious File
Rule Categories::Operating Systems::Windows
Rule Categories::Policy::Other
Vulnerability::Severity::Medium
Vulnerability::Severity::Critical
Vulnerability::Severity::High
N/A
Not Applicable
CVE-2025-21247 |
Loading description
|