Netskope Threat Labs

FILE-OFFICE Microsoft Office Equation Editor stack buffer overflow attempt

IPS-CFWIPS-SWG

1 SID: 54620

First seen
February 2022
Last seen
October 2026

Detects a document exploiting CVE-2017-11882, the stack buffer overflow in Microsoft's legacy Equation Editor that can allow code execution without macros. The rule matches the object data stream carrying the crafted equation record that overflows the font name buffer.