Stats
- First seen
- July 2022
- Last seen
- October 2026
Description
Detects a document exploiting CVE-2016-4324, a use-after-free in LibreOffice's RTF stylesheet parsing that can allow code execution. The rule matches the stylesheet directives that public exploits use to free style objects while the parser still references them.