SOC336 | Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)
Platform: LetsDefend Date Investigated: February 04, 2025 Severity: Critical Verdict: True Positive ✅ File Quarantined: No Summary A phishing email carrying a password-protected RTF attachment landed
Platform: LetsDefend Date Investigated: February 04, 2025 Severity: Critical Verdict: True Positive ✅ File Quarantined: No
Summary
A phishing email carrying a password-protected RTF attachment landed in Austin's inbox at 05:12 AM on Feb 04, 2025. The attachment exploited CVE-2025-21298, a Windows OLE zero-click remote code execution vulnerability, meaning the exploit triggered without Austin needing to explicitly run anything. The endpoint contacted a malicious IP address roughly three hours after the email arrived, confirming execution. The file was never quarantined automatically.
Alert Details
| Field | Value |
|---|---|
| Event ID | 314 |
| Event Time | Feb 04, 2025, 04:18 PM |
| Rule | SOC336, Windows OLE Zero-Click RCE Exploitation Detected |
| CVE | CVE-2025-21298 |
| Target | Austin@letsdefend.io |
| File | mail.rtf |
| File Hash, MD5 | df993d037cdb77a435d6993a37e7750dbbb16b2df64916499845b56aa9194184 |
| VT Detection | 29/62 vendors flagged as malicious |
| C2 IP | 84.38.130.118 |
The Email
The delivery mechanism was a phishing email designed to look routine. The sender address was projectmanagement@pm.me and the subject line read "Important: Action Required for Upcoming Project Deadline." The body told Austin to review the attached document for project details. Nothing in the content itself would immediately raise suspicion to a regular employee.
The attachment was mail.rtf and it came with a password: infected.
That password is not there for the recipient's benefit. It is there to stop email security gateways from inspecting the file contents. A password-protected attachment cannot be scanned by most automated tools since they cannot open it. The attacker is using the password as an evasion layer, not a protection layer.
CVE-2025-21298 and Why RTF Matters
CVE-2025-21298 is a remote code execution vulnerability in the Windows OLE (Object Linking and Embedding) subsystem, patched by Microsoft in January 2025. RTF files are a natural delivery vehicle for OLE exploits because the format supports embedded OLE objects natively and has a long history of being abused for exactly this reason.
The "zero-click" label in the rule name is the important part here. This vulnerability can be triggered without the user explicitly running the file, previewing the RTF in Windows Explorer's Preview Pane is enough in some cases. That means even a cautious user who did not double-click to open the document could still trigger the exploit just by selecting the file.
Timeline
Feb 04, 2025 05:12 AM Email delivered to Austin, action: Allowed
↓
Austin's endpoint receives mail.rtf (password-protected, bypasses scanner)
↓
Feb 04, 2025 08:06:42 AM Endpoint contacts C2 at 84.38.130.118
↓
CVE-2025-21298 confirmed as exploited, RCE achieved
↓
Feb 04, 2025 04:18 PM Alert fires (SOC336)
The roughly three hour gap between email delivery and C2 contact lines up with a user arriving at their desk and previewing or opening the file during normal work hours.
Hash Reputation Check
The MD5 hash returned a 29 out of 62 detection ratio on VirusTotal. That is not as high as some cases but it is well past the threshold for calling it malicious. Just under half of all major security engines flagged it, which is more than enough when combined with the active C2 contact as corroborating evidence.
C2 Contact
Firewall logs show the endpoint reaching out to 84.38.130.118 at 08:06:42 AM on the same day the email arrived. The timing is consistent with the exploit running after Austin interacted with the file. The file was allowed to execute since the automatic action on the email was set to Allowed, which means there was no prevention layer that stopped the attachment from landing and no EDR block that caught the exploit running.
MITRE ATT&CK Mapping
| Technique | ID | Description |
|---|---|---|
| Spearphishing Attachment | T1566.001 | RTF delivered via targeted phishing email |
| Exploitation for Client Execution | T1203 | CVE-2025-21298 OLE RCE triggered on open or preview |
| Obfuscated Files or Information | T1027 | Password protection used to bypass email scanner |
| Application Layer Protocol | T1071 | C2 communication over standard network protocol |
Playbook Answers
✅ Check If Someone Requested the C2
✅ Analyze Malware
✅ Check if the Malware is Quarantined and Cleaned
Verdict and Closing Rationale
True Positive. A phishing email with a password-protected RTF exploiting CVE-2025-21298 was delivered to Austin and allowed through. The endpoint contacted a malicious IP three hours after delivery, confirming the exploit executed. The file was never automatically quarantined. Austin's endpoint should be treated as compromised and contained pending a full forensic review since RCE means the attacker had arbitrary code execution on the machine.
Takeaway for Future Cases
Two things stand out here. First, a password-protected attachment should always raise immediate suspicion in a phishing context, it is a well known technique specifically for bypassing email security scanning and there is almost no legitimate reason to send a password-protected RTF to a colleague. Second, zero-click or low-interaction vulnerabilities like CVE-2025-21298 break the assumption that a cautious user who does not run attachments is safe. If the exploit fires on preview, user behaviour is not a reliable defence and the prevention layer has to catch it before it lands.
Originally published on Hashnode.