Netskope Threat Labs

FILE-OFFICE RTF objautlink url moniker file download attempt

IPS-SWG

1 SID: 42189

First seen
January 2022
Last seen
October 2026

Detects an RTF document exploiting CVE-2017-0199, the OLE2link flaw that fetches and executes remote content when the document renders, without macros. The rule matches the automatic link object carrying the URL moniker that points at the operator-controlled payload.