Netskope Threat Labs

FILE-OFFICE Microsoft MSHTML Remote Code Execution Vulnerability

IPS-SWG

2 SIDs: 140826, 150778

First seen
September 2022
Last seen
August 2026

Detects content exploiting CVE-2021-40444, the remote code execution flaw in Microsoft's MSHTML engine reached through Office documents and crafted web content. The rule matches a second variant of the exploit payload that saw active exploitation before the fix.