Tag
high
advisory
MSBuild Started by Microsoft Office Application
2 rules 2 TTPsThe Microsoft Build Engine (MSBuild) being started by a Microsoft Office application is an unusual behavior that could indicate a malicious document is executing a payload to evade defenses and execute code.
Word +2
defense-evasion
execution
msbuild
office-macro
2r
2t
medium
advisory
XSL Script Execution via COM Interface in Microsoft Office
2 rules 5 TTPsAdversaries may exploit Microsoft Office applications to execute malicious JScript or VBScript by leveraging the Microsoft.XMLDOM COM interface to process and transform XML documents using XSL scripts, potentially leading to initial access or defense evasion.
Microsoft Office +3
xsl-script
com-interface
office-macro
2r
5t
high
advisory
Microsoft Office for Mac Sandbox Escape via Faulty Regex
2 rules 3 TTPsA vulnerability in Microsoft Office for Mac allows malicious code to escape the application's sandbox and achieve persistence by abusing a faulty regex for temporary files.
Microsoft Word
sandbox-escape
persistence
office-macro
macos
2r
3t