Netskope Threat Labs

FILE-OFFICE CVE-2017-0199 HTA payload

IPS-CFWIPS-SWG

1 SID: 152019

First seen
November 2024
Last seen
August 2026

Detects documents delivering an HTML application payload through CVE-2017-0199, the Office OLE2link flaw that runs remote script from a document. The rule matches the obfuscated PowerShell and launcher strings from public exploit generators, and code runs without macros if the victim opens the document.