MS Word MS WordPad via IE VBS Engine RCE
# CVE-2018-8174
MS Word MS WordPad via IE VBS Engine RCE
MS Word and MS WordPad RCE via IE VBS RCE
https://github.com/smgorelik/Windows-RCE-exploits/tree/master/Web/VBScript
Save the index.html to webserver
then use the python script to generate RTF Exploit
Shellcode is static Down\Exec Putty.exe from main website
check index.html for the shellcode
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view