Description
Detects a document exploiting CVE-2017-11826, a type confusion in Microsoft Office's embedded font object handling that can allow code execution. The rule matches the crafted font structures that public exploits use to confuse the parser during rendering.