PoC Archive PoC Archive

tag

Rtf

  • CVE-2026-21514, CVE-2026-21510 social-engineering HIGH KEV

    RTF Protected-View Bypass (CVE-2026-21514) Chained with ShellLink RCE (CVE-2026-21510) — Builder Scripts

    This repository contains two small builder scripts used to research a document-based attack chain: genrtf.py assembles a malicious RTF file containing an embedded OLE object whose payload is a hex-encoded UNC path (\\127.0.0.1@80\final.lnk) to a remotely…

    Unverified 2026-07-05
  • CVE-2025-21298 binary CRITICAL 9.8 EPSS 81%

    Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)

    CVE-2025-21298 is a critical Windows OLE memory-corruption vulnerability in ole32.dll that can be triggered through malicious RTF content. In Outlook scenarios, preview-pane rendering is sufficient to trigger the vulnerable parsing flow, making this…

    Patched 2026-05-16