Skip to content
Abdullah
securityletsdefendcase-study

SOC336 | Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)

Platform: LetsDefend Date Investigated: February 04, 2025 Severity: Critical Verdict: True Positive ✅ File Quarantined: No Summary A phishing email carrying a password-protected RTF attachment landed

1 min read

Platform: LetsDefend Date Investigated: February 04, 2025 Severity: Critical Verdict: True Positive ✅ File Quarantined: No

Summary

A phishing email carrying a password-protected RTF attachment landed in Austin's inbox at 05:12 AM on Feb 04, 2025. The attachment exploited CVE-2025-21298, a Windows OLE zero-click remote code execution vulnerability, meaning the exploit triggered without Austin needing to explicitly run anything. The endpoint contacted a malicious IP address roughly three hours after the email arrived, confirming execution. The file was never quarantined automatically.

Alert Details

Field Value
Event ID 314
Event Time Feb 04, 2025, 04:18 PM
Rule SOC336, Windows OLE Zero-Click RCE Exploitation Detected
CVE CVE-2025-21298
Target Austin@letsdefend.io
File mail.rtf
File Hash, MD5 df993d037cdb77a435d6993a37e7750dbbb16b2df64916499845b56aa9194184
VT Detection 29/62 vendors flagged as malicious
C2 IP 84.38.130.118

The Email

The delivery mechanism was a phishing email designed to look routine. The sender address was projectmanagement@pm.me and the subject line read "Important: Action Required for Upcoming Project Deadline." The body told Austin to review the attached document for project details. Nothing in the content itself would immediately raise suspicion to a regular employee.

The attachment was mail.rtf and it came with a password: infected.

That password is not there for the recipient's benefit. It is there to stop email security gateways from inspecting the file contents. A password-protected attachment cannot be scanned by most automated tools since they cannot open it. The attacker is using the password as an evasion layer, not a protection layer.

CVE-2025-21298 and Why RTF Matters

CVE-2025-21298 is a remote code execution vulnerability in the Windows OLE (Object Linking and Embedding) subsystem, patched by Microsoft in January 2025. RTF files are a natural delivery vehicle for OLE exploits because the format supports embedded OLE objects natively and has a long history of being abused for exactly this reason.

The "zero-click" label in the rule name is the important part here. This vulnerability can be triggered without the user explicitly running the file, previewing the RTF in Windows Explorer's Preview Pane is enough in some cases. That means even a cautious user who did not double-click to open the document could still trigger the exploit just by selecting the file.

Timeline

Feb 04, 2025 05:12 AM  Email delivered to Austin, action: Allowed
        ↓
        Austin's endpoint receives mail.rtf (password-protected, bypasses scanner)
        ↓
Feb 04, 2025 08:06:42 AM  Endpoint contacts C2 at 84.38.130.118
        ↓
        CVE-2025-21298 confirmed as exploited, RCE achieved
        ↓
Feb 04, 2025 04:18 PM  Alert fires (SOC336)

The roughly three hour gap between email delivery and C2 contact lines up with a user arriving at their desk and previewing or opening the file during normal work hours.

Hash Reputation Check

The MD5 hash returned a 29 out of 62 detection ratio on VirusTotal. That is not as high as some cases but it is well past the threshold for calling it malicious. Just under half of all major security engines flagged it, which is more than enough when combined with the active C2 contact as corroborating evidence.

C2 Contact

Firewall logs show the endpoint reaching out to 84.38.130.118 at 08:06:42 AM on the same day the email arrived. The timing is consistent with the exploit running after Austin interacted with the file. The file was allowed to execute since the automatic action on the email was set to Allowed, which means there was no prevention layer that stopped the attachment from landing and no EDR block that caught the exploit running.

MITRE ATT&CK Mapping

Technique ID Description
Spearphishing Attachment T1566.001 RTF delivered via targeted phishing email
Exploitation for Client Execution T1203 CVE-2025-21298 OLE RCE triggered on open or preview
Obfuscated Files or Information T1027 Password protection used to bypass email scanner
Application Layer Protocol T1071 C2 communication over standard network protocol

Playbook Answers

  • ✅ Check If Someone Requested the C2

  • ✅ Analyze Malware

  • ✅ Check if the Malware is Quarantined and Cleaned

Verdict and Closing Rationale

True Positive. A phishing email with a password-protected RTF exploiting CVE-2025-21298 was delivered to Austin and allowed through. The endpoint contacted a malicious IP three hours after delivery, confirming the exploit executed. The file was never automatically quarantined. Austin's endpoint should be treated as compromised and contained pending a full forensic review since RCE means the attacker had arbitrary code execution on the machine.

Takeaway for Future Cases

Two things stand out here. First, a password-protected attachment should always raise immediate suspicion in a phishing context, it is a well known technique specifically for bypassing email security scanning and there is almost no legitimate reason to send a password-protected RTF to a colleague. Second, zero-click or low-interaction vulnerabilities like CVE-2025-21298 break the assumption that a cautious user who does not run attachments is safe. If the exploit fires on preview, user behaviour is not a reliable defence and the prevention layer has to catch it before it lands.

Originally published on Hashnode.