<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rtf — PoC Archive</title><link>https://poc.intelseclab.com/tags/rtf/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/rtf/index.xml" rel="self" type="application/rss+xml"/><item><title>RTF Protected-View Bypass (CVE-2026-21514) Chained with ShellLink RCE (CVE-2026-21510) — Builder Scripts</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21514-cve-2026-21510-rtf-lnk-builder/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21514-cve-2026-21510-rtf-lnk-builder/</guid><description>High severity — social-engineering · CVE-2026-21514, CVE-2026-21510. Status: PoC. Affects: Microsoft Office (RTF/Word rendering + Protected View) and Windows Shell Link (.lnk) handling. Tags: rtf, lnk, ole-object, protected-view-bypass, cve-2026-21514, cve-2026-21510, phishing, initial-access.</description><category>social-engineering</category><category>High</category><category>rtf</category><category>lnk</category><category>ole-object</category><category>protected-view-bypass</category><category>cve-2026-21514</category><category>cve-2026-21510</category><category>phishing</category><category>initial-access</category></item><item><title>Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_cve-2025-21298-outlook-rtf-rce/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_cve-2025-21298-outlook-rtf-rce/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2025-21298. Status: Researched. Affects: Microsoft Windows OLE (ole32.dll) as reached by Outlook/Word RTF parsing. Tags: RCE, zero-click, Outlook, RTF, OLE, ole32, Windows, memory-corruption, unauthenticated.</description><category>binary</category><category>Critical</category><category>RCE</category><category>zero-click</category><category>Outlook</category><category>RTF</category><category>OLE</category><category>ole32</category><category>Windows</category><category>memory-corruption</category><category>unauthenticated</category></item></channel></rss>