Netskope Threat Labs

FILE-OFFICE Microsoft Windows Outlook remote code execution attempt

IPS-CFWIPS-SWG

1 SID: 66458

Detects email content exploiting CVE-2026-40361, a remote code execution flaw in Microsoft Outlook. The rule matches the crafted property structures that public exploits use to corrupt memory when the client processes the message.