Netskope Threat Labs

FILE-OFFICE Microsoft Office Outlook HTML acronym tag memory corruption attempt

IPS-CFW

1 SID: 46602

Detects an email exploiting CVE-2018-8161, memory corruption in Outlook's HTML rendering that can allow code execution. The rule matches the acronym and style markup that public exploits use to corrupt memory when the message displays.