Netskope Threat Labs

FILE-OFFICE Microsoft Office remote code execution attempt

IPS-CFWIPS-SWG

5 SIDs: 45654, 64858, 65033, 65097, 66475

First seen
December 2022
Last seen
October 2026

Detects documents exploiting remote code execution vulnerabilities across Microsoft Office components, including CVE-2025-30377, CVE-2025-47164, CVE-2024-38021, and others. The rule matches the crafted record structures that public exploits use to corrupt memory during document parsing.