Home / os / win10

Microsoft Office Word MSHTML Remote Code Execution

Posted on 09 December 2021

This Metasploit module creates a malicious docx file that when opened in Word on a vulnerable Windows system will lead to code execution. This vulnerability exists because an attacker can craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine.

 

TOP