
Generates weaponized JPEG files exploiting CVE-2025-50165 (Windows Graphics RCE) with custom x64 shellcode, heap spray, ROP chain, and AV/EDR evasion for authorized penetration testing.
Critical Remote Code Execution via malicious JPEG – Windows 11 24H2 (unpatched)
CVSS 9.8 – No privileges, no interaction required
CVE-2025-50165 - windowscodecs.dll untrusted pointer dereference
Discovered by Zscaler ThreatLabz
Patched: November 2025 (KB5040442)
poc/ → Final weaponized JPEGs
scripts/generate_poc.py → Main generator (Encrypter15)
shellcode/calc_x64.bin → Raw shellcode for analysis
README.md → This file
pip install Pillow
python scripts/generate_poc.py
→ Generates poc/CVE-2025-50165_x64_encrypter15.jpg
Open the JPEG with Photos, Office, Edge preview, etc. → calc.exe spawns instantly on vulnerable systems.
For authorized security testing and research only. Do not use against systems without explicit permission.
Encrypter15 – [email protected]
Stay frosty.