Re: Microsoft Office – OLE Packager allows code execution in all Office versions, with macros disabled and high security templates applied

Posted by Kevin Beaumont on Jul 03

All – it is probably bad form to respond to my own post, but I’ve seen some
folk dismiss this out of hand on social media so I wanted to provide two
VERY QUICK proof of concept examples. These were just put together in 10
minutes.

http://owned.lab6.com/~gossi/research/public/packager/

There’s an RTF and .docx version.

You should be able to email these to colleagues. The “Sales Invoice” file
is a .js file executed in…

Leave a Reply