FILE-OFFICE -- Snort detected traffic targeting vulnerabilities in files belonging to the Microsoft Office suite of software (Excel, PowerPoint, Word, Visio, Access, Outlook, etc.).
FILE-OFFICE Microsoft Office Equation Editor RTF evasion attempt
This event is generated when an RTF file that is seen using the vulnerable Equation Editor in Microsoft Office. Impact: Potential Code Execution Details: This rule targets an APT campaign leveraging CVE-2018-0798 which exploits an undisclosed vector in the Equation Editor for Microsoft Office. In general, this CLSID should only be seen in malicious activity. Ease of Attack: Easy
No information provided
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
CVE-2018-0802 |
Loading description
|
CVE-2018-0798 |
Loading description
|