Netskope Threat Labs

FILE-OFFICE Microsoft Office RTF object remote code execution attempt

IPS-SWG

2 SIDs: 62054, 150649

First seen
December 2023
Last seen
October 2026

Detects an RTF document exploiting CVE-2015-2369 or CVE-2023-36884, remote code execution flaws reached through embedded object links. The rule matches the automatic link object data that pulls remote content into the document's execution context.