Stats
- First seen
- November 2024
- Last seen
- August 2026
Description
Detects documents delivering an HTML application payload through CVE-2017-0199, the Office OLE2link flaw that runs remote script from a document. The rule matches the obfuscated PowerShell and launcher strings from public exploit generators, and code runs without macros if the victim opens the document.
