Rule Category

FILE-OFFICE -- Snort detected traffic targeting vulnerabilities in files belonging to the Microsoft Office suite of software (Excel, PowerPoint, Word, Visio, Access, Outlook, etc.).

Alert Message

FILE-OFFICE Microsoft Office security feature bypass attempt

Rule Explanation

This rule looks for RTF control words that are known to bypass OLE security mitigations in Microsoft Office products. Attackers can leverage this vulnerability to execute arbitrary OLE objects and potentially gain remote code execution.

What To Look For

This rule looks for attempts to exploit a security bypass in Microsoft Office.

Known Usage

No public information

False Positives

Known false positives, with the described conditions

This rule can trigger on valid RTF files.

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Additional Links

Rule Vulnerability

Authentication Bypass

An Authentication Bypass occurs when there is a way to avoid providing user credentials to a system before performing restricted operations on said system.

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2026-21514
Loading description