Netskope Threat Labs

FILE-OFFICE Microsoft Office Equation Editor object stack buffer overflow attempt

IPS-CFWIPS-SWG

3 SIDs: 45133, 49775, 200045

First seen
August 2022
Last seen
September 2026

Detects a document exploiting CVE-2017-11882, the stack buffer overflow in Microsoft's legacy Equation Editor that can allow code execution without macros. The rule matches the automatic object update directive that pulls in the vulnerable equation object, one of the most reused maldoc exploits of its era.