Netskope Threat Labs

FILE-OFFICE Microsoft Office Word OLMAPI32.dll dll-load exploit attempt

IPS-SWG

1 SID: 37589

First seen
May 2023
Last seen
September 2026

Detects a document exploiting CVE-2016-0042, a dynamic link library loading flaw in Microsoft Office that can allow code execution. Opening a document from a writable location loads the referenced mail library from the document directory, an operator-controlled path.