Description
Detects an Excel workbook exploiting remote code execution vulnerabilities in Microsoft Excel, including CVE-2025-21354, CVE-2025-21362, CVE-2025-49696, CVE-2025-47162, and CVE-2025-47167. The rule matches crafted workbook record structures that public exploits use to corrupt memory during parsing.