We are also receiving this almost daily in the two forms below. It shows Internet explorer and Outlook triggering these. Has there been any response on whether this is a false positive? We had 19 in one day and daily since then.
Exploit code executing from stack blocked BLOCK tlee Adobe Reader C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe Attacked application: C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe; Parent process name: OUTLOOK.EXE;
5/27/2018 2:03:07 AM W7682 10.60.11.4 Exploit code executing from stack blocked BLOCK Hotel_front_desk Adobe Reader C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe Attacked application: C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe; Parent process name: iexplore.exe; Layer: Protection Against OS Security Bypass; API ID: 450; Address: 0x033ACC4C; Module: ; AddressType: ; StackTop: 0x033B0000; StackBottom: 0x03394000; StackPointer: ; Extra: