Skip to content
This repository was archived by the owner on Aug 26, 2026. It is now read-only.

Latest commit

 

History

13 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

XWorm RCE PoC

Warning

This project was created strictly for educational, research, and authorized security testing purposes!
The authors take no responsibility for your actions or any damage caused by this software!

image

🇷🇺 Читать на Русском


❓ F.A.Q

Q. What is this? Proof of Concept (PoC) for a Zero-Click Remote Code Execution (RCE) vulnerability on the XWorm server.

Q. How does the vulnerability work? XWorm contains an input sanitization vulnerability in its RDP connection plugin:

  1. The client sends connection data to the server.
  2. The server constructs a command line and launches mstsc.exe (the built-in Windows RDP client) with the provided arguments.
  • The server does not validate or sanitize the client's response;
  • An attacker doesn't even need the server operator to manually issue a request to the plugin.

💻 Usage

  1. Download the binary from the Releases section (or compile it from source).
  2. Enter the required details for the target server.
  3. Enter the command you want to execute on the server side.
  4. Send the payload.

Note

For safety reasons, research this strictly inside an isolated virtual machine (VM).


#FuckXWorm

About

Proof of concept Zero-click exploit in XWorm.

Topics

Resources

Stars

18 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages