Stats
- First seen
- September 2022
- Last seen
- August 2026
Description
Detects content exploiting CVE-2021-40444, the remote code execution flaw in Microsoft's MSHTML engine reached through Office documents and crafted web content. The rule matches a second variant of the exploit payload that saw active exploitation before the fix.


