Netskope Threat Labs

FILE-OFFICE Document Foundation LibreOffice RTF stylesheet use after free attempt

IPS-SWG

1 SID: 39148

First seen
July 2022
Last seen
October 2026

Detects a document exploiting CVE-2016-4324, a use-after-free in LibreOffice's RTF stylesheet parsing that can allow code execution. The rule matches the stylesheet directives that public exploits use to free style objects while the parser still references them.