Netskope Threat Labs

FILE-OFFICE Microsoft Office RTF malformed pfragments field

IPS-SWG

1 SID: 18680

First seen
February 2022
Last seen
October 2026

Detects an RTF document exploiting CVE-2010-3333, the stack buffer overflow in Word's pFragments object parsing that can allow code execution without macros. The flaw became a fixture of targeted attack toolkits after public exploit code appeared.