Rule Category

Alert Message

Rule Explanation

This event is generated when a malicious excel file that triggers a stack buffer overflow in Microsoft JET Database Engine is observed. Impact: Potential Code Execution Details: A malicious Excel file containing an invalid string length can allow an attacker to overwrite an adjacent global pointer. The resulting memcpy could allow for code execution. Ease of Attack:

What To Look For

Known Usage

No public information

False Positives

No known false positives


MITRE ATT&CK Framework



For reference, see the MITRE ATT&CK vulnerability types here:

Additional Links

CVE Additional Information