Netskope Threat Labs

FILE-OFFICE AntennaHouse DMC ParseEnvironment heap buffer overflow attempt

IPS-SWG

1 SID: 41759

First seen
November 2022
Last seen
October 2026

Detects a Microsoft Office document exploiting CVE-2017-2797, a heap buffer overflow in the Antenna House document conversion component that can allow code execution when the parser processes a crafted compound document.