
Proof-of-concept exploit for CVE-2019-12735 demonstrating arbitrary command execution via Vim/Neovim modeline feature. Includes shellcode injection and reverse shell payload generation for educational security testing.
Prerequisite: modeline feature must be enabled.
For regular users, modeline is enabled by default, while for root users it is disabled by default.
Use echo &modeline to check the status: 1 means enabled, 0 means disabled.
If not, you can add set modeline to ~/.vimrc (create the file if it does not exist).
When writing manually, note that the escape character x1b is a non-printable character.
To modify the second part of the exploit code, a simple method is to download the source file and modify the command execution part. Alternatively, you can write or modify it using a binary editor.
poc.txt:
vim poc.txt
shell.txt:
nc -lvp 9999
vim shell.txt
then you can get a shell
set nomodeline to vimrc to disable modeline.