
CVE-2018-8581
CVE-2018-8581

CVE-2018-8581

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

Python-based CLI for automated red team infrastructure deployment on AWS and Digital Ocean, with modular support for C2, email servers, HTTP…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

A tool to abuse Exchange services

Proof of Concept for CVE-2023-23397 in Python

Proof-of-concept exploit for CVE-2023-23397, an Outlook/Exchange privilege escalation vulnerability that triggers NTLM credential theft via a…

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

Open-source offensive security platform for conducting phishing campaigns that weaponizes iCalendar automatic event processing.

Cisco Email Security Appliance: Email to zero-click RCE as root - Remote Code Execution/Memory Corruption/ROP-chain

Educational guide on CVE-2024-21413, the Outlook zero-click Moniker Link vulnerability, covering attack flow, NTLM credential capture, detection with…

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP-based phishing email delivery, malicious RTF attachment generation, and…

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC