Stats
- First seen
- May 2023
- Last seen
- September 2026
Description
Detects a document exploiting CVE-2016-0042, a dynamic link library loading flaw in Microsoft Office that can allow code execution. Opening a document from a writable location loads the referenced mail library from the document directory, an operator-controlled path.