Netskope Threat Labs

FILE-OFFICE Microsoft Office Word wwlib.dll out of bounds read attempt

IPS-SWG

1 SID: 39203

First seen
January 2023
Last seen
May 2026

Detects a document exploiting CVE-2015-2469 or CVE-2016-3234, out-of-bounds reads in Word's document parsing library that can leak memory. The rule matches the mail merge structures that public exploits use to read beyond allocated buffers.