MS Word MS WordPad via IE VBS Engine RCE
# CVE-2018-8174
MS Word MS WordPad via IE VBS Engine RCE
MS Word and MS WordPad RCE via IE VBS RCE
https://github.com/smgorelik/Windows-RCE-exploits/tree/master/Web/VBScript
Save the index.html to webserver
then use the python script to generate RTF Exploit
Shellcode is static Down\Exec Putty.exe from main website
check index.html for the shellcode
登录后查看神龙缓存的 POC 文件快照
登录查看