Stats
- First seen
- January 2022
- Last seen
- October 2026
Description
Detects an RTF document exploiting CVE-2017-0199, the OLE2link flaw that fetches and executes remote content when the document renders, without macros. The rule matches the automatic link object carrying the URL moniker that points at the operator-controlled payload.
