Netskope Threat Labs

FILE-OFFICE Microsoft Office HTML remote code execution attempt

IPS-SWG

2 SIDs: 62540, 152002

First seen
November 2023
Last seen
October 2026

Detects a document exploiting CVE-2023-36884, the Office and Windows HTML remote code execution flaw that runs code without macros. The rule matches the embedded remote template chunks that the exploit uses to fetch ActiveX content, and the flaw saw exploitation in targeted campaigns before the July 2023 fix.