Stats
- First seen
- January 2023
- Last seen
- May 2026
Description
Detects a document exploiting CVE-2015-2469 or CVE-2016-3234, out-of-bounds reads in Word's document parsing library that can leak memory. The rule matches the mail merge structures that public exploits use to read beyond allocated buffers.