Stats
- First seen
- July 2024
- Last seen
- October 2026
Description
Detects a document reaching the InfoPath Designer interfaces through embedded OLE automation, the path for CVE-2016-0021 code execution. The rule matches the hex-encoded control identifiers that public exploits use to invoke the vulnerable component from Word.