Stats
- First seen
- May 2023
- Last seen
- September 2026
Description
Detects a document exploiting CVE-2018-16858, a flaw in LibreOffice's macro handling that runs scripts through traversal paths in the scripting scheme. The rule matches the script references that point the interpreter at operator-controlled code without a macro prompt.