Stats
- First seen
- March 2022
- Last seen
- October 2026
Description
Detects an RTF document exploiting CVE-2018-0802 or CVE-2018-0798 through crafted embedded object declarations. The rule matches the component identifiers of Office scripting and shell objects that the exploit chains into after the initial equation corruption.
