Netskope Threat Labs

FILE-OTHER LibreOffice macro remote code execution attempt

IPS-SWG

2 SIDs: 51098, 51101

First seen
May 2023
Last seen
September 2026

Detects a document exploiting CVE-2018-16858, a flaw in LibreOffice's macro handling that runs scripts through traversal paths in the scripting scheme. The rule matches the script references that point the interpreter at operator-controlled code without a macro prompt.