Netskope Threat Labs

BROWSER-PLUGINS Microsoft Office Outlook View OVCtl ActiveX clsid access

IPS-SWG

1 SID: 8422

First seen
January 2022
Last seen
October 2026

Detects web content instantiating the Microsoft Outlook View ActiveX control by its class identifier. The control exposes Outlook data and system interfaces to scripts, and researchers have demonstrated that crafted method calls reach command execution, matching CVE-2001-0538 and CVE-2017-11774.