FILE-OFFICE -- Snort detected traffic targeting vulnerabilities in files belonging to the Microsoft Office suite of software (Excel, PowerPoint, Word, Visio, Access, Outlook, etc.).
FILE-OFFICE Microsoft Office Outlook appointment privilege escalation attempt
This rule looks for crafted email messages that contain a UNC path in a PidLidReminderFileParameter message property.
This rule alerts on traffic that exploits the vulnerability outlined in CVE-2023-23397.
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None
Tactic: Initial Access
Technique: Exploit Public-Facing Application
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org