Stats
- First seen
- February 2022
- Last seen
- October 2026
Description
Detects a document exploiting CVE-2017-11882, the stack buffer overflow in Microsoft's legacy Equation Editor that can allow code execution without macros. The rule matches the object data stream carrying the crafted equation record that overflows the font name buffer.


