Netskope Threat Labs

FILE-OFFICE Microsoft Office Word ipdesign.dll ActiveX object access attempt

IPS-SWG

2 SIDs: 38126, 38127

First seen
July 2024
Last seen
October 2026

Detects a document reaching the InfoPath Designer interfaces through embedded OLE automation, the path for CVE-2016-0021 code execution. The rule matches the hex-encoded control identifiers that public exploits use to invoke the vulnerable component from Word.