Netskope Threat Labs

FILE-OFFICE Microsoft Office OLE UtOlePresStmToContentsStm memory corruption attempt

IPS-CFWIPS-SWG

2 SIDs: 64615, 64617

First seen
March 2025
Last seen
October 2026

Detects an RTF document exploiting CVE-2025-21298, memory corruption in Windows OLE presentation stream handling that can allow code execution when the document renders. The rule matches the embedded object data that drives the vulnerable stream conversion.