Feed/CVE-2025-21298
CVE-2025-21298CRITICALCVSS 9.8

CVE-2025-21298

Published Jan 14, 2025·Updated Jun 17, 2026

NVD Description

Windows OLE Remote Code Execution Vulnerability

Public Exploits & PoCs9 found

PoC: SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

SOC336 - Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298) Walkthrough

PoC: LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298

LetsDefend SOC336 case study on CVE-2025-21298

PoC: Zero-Click-RCE-Incident-Response-CVE-2025-21298

Technical investigation and host containment of a Critical-severity Zero-Click RCE exploit (CVE-2025-21298) using EDR telemetry and static malware analysis.

PoC: LetsDefend-SOC336-Windows-OLE-Zero-Click-RCE-Exploitation-Detected-CVE-2025-21298-

We are expected to investigate a critical alert reporting a Windows OLE zero-click RCE exploitation (CVE-2025-21298) delivered via a malicious RTF attachment.

PoC: full-poc-CVE-2025_21298

Complete analysis of CVE-2025-21298, a double free vulnerability related to ole32 library in windows.

PoC: Blackash-CVE-2025-21298

CVE-2025-21298

PoC: rtf-ctf-cve-2025-21298

A safe CTF challenge demonstrating CVE-2025-21298 using RTF and OLE objects.

PoC: CVE-2025-21298

A Critical Windows OLE Zero-Click Vulnerability

PoC: CVE-2025-21298

Proof of concept & details for CVE-2025-21298

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free