Acrobat prototype-pollution PoC/exploit pattern — CVE-2026-34621 related
critical
CVE_2026_34621_RELATED
PDF JavaScript combines Acrobat prototype pollution targeting privileged state with an execution or sensitive file-read primitive.
Embedded TrueType font has malformed EBLC/EBDT bitmap-glyph placement plus the EBSC max-range table trap.
PDF JavaScript uses Acrobat internal share/login APIs, swConn prototype manipulation, and privileged RSS/file-read APIs.
PDF combines RichMedia Flash activation, a crafted SWF with authplay-era markers, and shellcode heap-spray staging.
Recovered SWF matches the public SWF9 DoABC CVE-2010-1297 newfunction trigger.
Recovered SWF matches the canonical SWF10 AVM1 CVE-2011-0611 trigger.
PDF combines RichMedia Flash activation with a crafted Run_Sploit/HeapSpray SWF or compact AS3 SWF plus PDF-side encoded shellcode.
PDF embeds a TrueType/OpenType SING font table together with JavaScript heap-spray shellcode.
PDF has an overlong trailer /ID and JavaScript dereferences this.docID.
PDF /DecodeParms predictor parameters force an integer overflow in the per-row buffer size.
Adobe Reader JPEG2000 JPX command payload exploit — CVE-2018-4990
critical
CVE_2018_4990_JPX_EMBEDDED_CMD
PDF embeds a malformed JPX/JPEG2000 image whose JP2 header area contains a command-execution/download payload.
PDF embeds the in-the-wild malformed JPEG2000 cmap construction used to trigger CVE-2018-4990.
PDF uses /Launch with shell parameters and an embedded/exported payload chain.
PDF contains XFA JavaScript that heap-sprays shellcode, builds a TIFF image payload, and assigns it to an XFA image rawValue.
PDF JavaScript reaches Android Java reflection through the Reader Mobile JavaScript bridge, obtains java.lang.Runtime, and loads an Android native/stage payload.
PDF JavaScript removes an app.addToolButton object from its cEnable callback and carries heap-spray shellcode.
PDF contains the XFA choiceList/oneOfChild trigger shape associated with CVE-2013-0640.
PDF combines RichMedia Flash activation, AS3 DoABC/SymbolClass SWF code, and PDF-side shellcode heap-spray staging.
PDF contains a crafted mailto URI that reaches mshta via path traversal and executes inline script.
PDF matches a CVE-2014-0496-specific Adobe Reader use-after-free primitive.
HTML or PDF-embedded HTML configures C6 Messenger DownloaderActiveX to download and run a file.
OOXML external OLEObject relationship targets HTML/CAB/MSHTML-style content.
Static evidence associated with CVE-2006-4694.
Static evidence associated with CVE-2008-0118.
Static evidence associated with CVE-2009-0658.
Static evidence associated with CVE-2009-3953.
Static evidence associated with CVE-2010-1797.
Static evidence associated with CVE-2010-2883-SHELLCODE-STAGE.
Static evidence associated with CVE-2011-2462.
PDF embeds a Flash SWF (RichMedia) and its de-obfuscated JavaScript heap-sprays to groom memory for the Flash exploit.
Word DDE field downloads and executes the observed CVE-2017-0262 second-stage URL.
PDF JavaScript calls Collab.collectEmailInfo() with a long or heap-sprayed message argument.
PDF JavaScript calls Collab.getIcon() with a long string argument.
OLE data contains the Composite Moniker CLSID with nearby scriptlet payload evidence.
PDF JavaScript invokes Doc.printSeps() with exploit-shaped arguments.
Document references EPSIMP32 or contains PostScript/EPS markers.
PDF embeds a crafted authplay-era SWF and pairs it with PDF-side shellcode heap-spray staging.
MTEF Matrix record exploit signature found in Equation Editor OLE data.
RTF contains an activated OLE1 Equation.3 object with large payload-like native data.
Equation Editor Ole10Native payload — CVE-2017-11882 family
critical
CVE_2017_11882_EQUATION_OLE10NATIVE_RELATED
RTF activates a Microsoft Equation 3.0 OLE storage carrying a high-entropy Ole10Native payload.
MTEF SIZE record contains an exploit-sized explicit point size or delta.
Equation Editor command stager — CVE-2017-11882 family
critical
CVE_2017_11882_COMMAND_STAGER_RELATED
Activated Equation Editor object carries command-launch bytes without a recoverable individual-CVE MTEF primitive.
Excel's shared-string index table (EXTSST) declares far more entries than the workbook's string count allows — the CVE-2011-0105 memory-corruption shape.
Excel FEATHEADER record declares an oversized/inconsistent internal length — the CVE-2009-3129 parser-overflow shape (legitimate records are only tens of bytes).
Excel HTML/XML workbook markup contains unexpected nested content in x:WorksheetOptions.
Legacy Excel BIFF8 workbook combines a narrow FORMAT-index cluster with large OLE slack payload staging.
Excel workbook has repeated malformed drawing-object (OBJ) records using an invalid target value, alongside shellcode/heap-spray context — the CVE-2009-0238 shape.
Excel workbook combines abnormal Forms.CommandButton OBJ record IDs with XLM/VBA auto-execution context.
Document contains an ms-msdt: URI consistent with Follina payload delivery.
PDF JavaScript matches the public Foxit Reader 9.0.1.1049 annotation-UAF exploitation chain.
Embedded PostScript/EPS uses Ghostscript CVE-2017-8291 exploitation primitives.
Embedded HWP EPS/PostScript matches the CVE-2013-0808 exploit staging shape.
HWPX BinData embeds a malformed prefixed OLE/CFB chart object with shellcode-style API markers.
RTF embeds a Word.Document.12 package with repeated null-CLSID ActiveX controls and an oversized activeX1.bin CFB payload.
Document contains a file:///\\ moniker-link target with an exclamation mark.
Document contains Shell.Explorer.1 CLSID evidence plus OLE activation context.
OLE2Link auto-activated remote loader — CVE-2017-0199 / CVE-2017-8759
critical
RTF_OLE2LINK_REMOTE_MONIKER_LOADER
RTF OLE2Link object is force-activated with \objupdate and fetches a remote second stage via an INCLUDE field.
Office document embeds EPS/PostScript with exploit-style dynamic execution or decode-filter markers.
Outlook .msg contains UNC reminder evidence: exact for ReminderFileParameter, related for raw UNC fallback.
Document XML/HTML contains an <img> tag with file://...!... moniker URL.
PDF font dictionary contains non-numeric FontMatrix values.
PowerPoint 95 native file has inconsistent PP7 directory lengths, sound-data marker, and nearby native payload bytes.
Binary PowerPoint stream contains an embedded .inf object reference with package data.
PowerPoint Document contains a malformed EscherClientTextbox with TextHeaderAtom, repeated-byte TextBytesAtom payload, and OutlineTextRefAtom.
RTF objdata embeds Word.Document.12 packages with many repeated ActiveX controls and oversized activeX1.bin.
RTF objdata embeds Word.Document.12 packages with many repeated ActiveX controls and oversized activeX1.bin.
OLE data contains the SOAP Moniker CLSID.
OLE Package CLSID found alongside executable file references.
OOXML .rels file contains an auto-load relationship Target pointing to a remote .rtf URL.
Decrypted Type 1 CharString matches the public callOtherSubr stack-pointer manipulation shape.
URL Moniker OLE link points to an HTA/script/template-style remote loader.
URL Moniker OLE link points to a remote loader.
PDF catalog uses a UTF-16BE /URI /Base value and JavaScript resolves a relative URL.
Decoded PDF shellcode invokes the NDProxy TAPI IOCTL 0x8fff23c8 with null-page kernel-stub setup.
Word/OLE data contains the MS15-022 local-zone exploit chain.
Word 97-era document places shellcode immediately before a malformed converter-facing table-SPRM cluster.
RTF font table with excessive entries — Word heap buffer overflow.
RTF contains an oversized pFragments value.
customUI ribbon part contains an external relationship target.
PDF embeds a file and JavaScript triggers the dataObjects ESObject use-after-free pattern.
PDF JavaScript calls the media.newPlayer API.
PDF JavaScript invokes util.printf() with an oversized format/string argument.
OLE data contains the ADODB.RecordSet CLSID.
Anomalous Equation Editor native stream — CVE-2018-0798 likely
high
CVE_2018_0798_EQUATION_NATIVE_ANOMALY
Embedded Equation Editor OLE data contains malformed, payload-like native stream bytes.
A CVE-2012-0158 RTF carries a large high-entropy binary blob — the encrypted/packed second-stage payload the shellcode drops.
PDF font data contains SING/CoolType markers inside font content.
RTF decodes to Equation.3 object activation without a recovered malformed native stream.
Raw email From header contains multiple parsed/angle-bracket addresses.
PDF automatic/open action uses GoToE or GoToR with a UNC /F target.
PDF uses JBIG2Decode/JBIG2 data alongside active content.
OLE data contains the MSCOMCTL.ListView CLSID.
OLE data contains the MSCOMCTL.Toolbar CLSID.
OLE data contains the MSScriptControl.ScriptControl CLSID.
Embedded JP2/JPEG2000 data has invalid, oversized, or truncated box sizes.
OOXML OLE2Link object fetches a remote Office-looking document.
OOXML linked OLE object auto-loads a remote URL without enough local evidence for an exact CVE.
Equation Editor MTEF Matrix record has an anomalous exploit-like shape.
Embedded JBIG2 data contains anomalous segment headers or sizes.
PDF action target contains a UNC path and the file has action triggers.
Document contains CVE-2026-21514-style Word/OLE bypass indicators.
RTF \listoverridecount with abnormally large value.
PDF JavaScript calls getAnnots() with an exploit-shaped argument.
PDF JavaScript invokes spell.customDictionaryOpen() with a long string argument.
PDF contains PRC 3D content markers.
PDF font data has SING/CoolType markers without the stricter validated CVE exploit shape.