Stats
- First seen
- November 2023
- Last seen
- October 2026
Description
Detects a document exploiting CVE-2023-36884, the Office and Windows HTML remote code execution flaw that runs code without macros. The rule matches the embedded remote template chunks that the exploit uses to fetch ActiveX content, and the flaw saw exploitation in targeted campaigns before the July 2023 fix.
