Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-4878 — Aggressor Script to just launch IE driveby for CVE-2018-4878 | Kitploit
Tools/GitHubGitHub/demonsec666/cve-2018-4878
Payload GenerationExploitationWeb Application ExploitationPenetration TestingCommand and ControlRed Teaming
GitHubdemonsec666/cve-2018-4878

CVE-2018-4878

Aggressor Script to just launch IE driveby for CVE-2018-4878

View Repository
38 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Author and Credits

Author: Vincent Yiu (@vysecurity)

Credits:

  • @evi1cg: Helping me test and keep me motivated
  • @smgoreli: Original Calc.exe PoC
  • @kbandla: He knows, and I know. ;)

Disclaimer

Developed to encourage more Aggressor script development. Use only in authorized penetration testing!

Description

Aggressor Script to launch an Internet Explorer driveby attack using CVE-2018-4878 exploit for Shockwave Flash player versions before February 2017.

Usage:

Video Demonstration: https://www.youtube.com/watch?v=JhUlOIEdq0s

  • Click Host > Host CVE-2018-4878 Payload > Host
  • Send link to victim or embed as part of other pages or a redirect
  • Victim hits link with IE and outdated flash, you get a shell back in IE sandbox.

CobaltStrike

  • Load CVE-2018-4878.cna
Download Tool