Equation Editor CLSID

RTF_EQUATION_EDITOR

← All detection heuristics · RTF

critical RTF_EQUATION_EDITOR

What it means

Equation Editor OLE CLSID (0002CE02) found in RTF hex data.

Why it fires

This CLSID instantiates the vulnerable Equation Editor component. CVE-2017-11882, CVE-2018-0802, and CVE-2018-0798 are among the most exploited Office vulnerabilities in history, and RTF is the most common delivery format.

Other RTF heuristics

RTF_OBJCLASS_EQUATION RTF_MZ_HEX RTF_DDEAUTO_REGSVR32_SCRIPTLET RTF_MACOS_ZSH_LOADER RTF_PACKAGE_AUTOLINK_DELIVERY RTF_OBJAUTLINK RTF_INCLUDE_REMOTE RTF_EXCESSIVE_HEX RTF_PACKAGE_OLE RTF_OBFUSCATION RTF_PHP_IRC_BOT_SOURCE RTF_OBJCLASS_PACKAGE RTF_REMOTE_TEMPLATE RTF_EXPLOIT_TEMPLATE_ARTIFACT RTF_OBJUPDATE_LOOSE_HEX_PAYLOAD RTF_OBJUPDATE RTF_PFRAGMENTS_RELATED RTF_OBJEMB RTF_WORD_COMPATIBILITY_PACKAGE RTF_OBJDATA RTF_OLEPRES_STREAM RTF_OLE10NATIVE_STREAM