Netskope Threat Labs

FILE-OFFICE Microsoft Word remote code execution attempt

IPS-SWG

1 SID: 62994

First seen
February 2024
Last seen
September 2026

Detects a document exploiting CVE-2024-21379, a remote code execution flaw in Microsoft Word's document parsing. The rule matches the crafted structures that public exploits use to corrupt memory when the document opens.