logo

An Inside Look into Microsoft Rich Text Format and OLE Exploits

ID: 2a353832-c472-5f2b-aaca-367d929cb3f1

STIX ID: report--2a353832-c472-5f2b-aaca-367d929cb3f1

Feed Name: McAfee Labs Blog

Threat Score
55/100

Date Published: 2020-01-24

Date Updated: 2026-04-28

Author: Chintan Shah

...
...

This McAfee technical report analyzes how attackers weaponize Microsoft RTF files via OLE functionality — describing RTF control words, overlay data, linked and embedded OLE objects (including Monikers and OLE packages), and examples tied to CVE-2015-1641, CVE-2017-0199, CVE-2017-8756 and CVE-2018-0802 — and recommends extracting and inspecting embedded/linked objects and streams to detect and mitigate these exploitation and malware delivery techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.