A remote code execution vulnerability affecting the Windows Themes component. The available information identifies the issue by product/component and impact class only, without public technical detail on the vulnerable function, root cause, attack vector specifics, or exploitation mechanism.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a functional proof-of-concept exploit for CVE-2023-38146 (ThemeBleed), targeting Windows 11 theme handling. The repo contains one main Python exploit script (themebleed.py), one C++ reverse-shell DLL template (rev_shell_template.cpp), one malicious theme template (theme_template.theme), a README, and dependency metadata. Core exploit flow: the Python script generates a malicious .theme file and a CAB-based .themepack, embedding a UNC path to an attacker SMB share (\\<attacker-ip>\tb\Aero.msstyles). It then starts an SMB server on port 445 using a modified impacket SimpleSMBServer subclass. The custom SMB2 create handler monitors the victim's file access sequence and, during the final verification-DLL retrieval stage, swaps the expected _vrf DLL request to Aero.msstyles_vrf_evil.dll. This is the key exploitation behavior enabling attacker-controlled DLL delivery. Payload behavior: if not run with --no-dll, the script auto-generates a malicious DLL source from rev_shell_template.cpp by replacing placeholders with attacker IP and port, compiles it with MinGW, and stores it under ./tb/Aero.msstyles_vrf_evil.dll. That DLL exports VerifyThemeVersion and opens a reverse shell by connecting back to the attacker and spawning powershell.exe or cmd.exe with socket-redirected standard handles. Repository structure and purpose: - themebleed.py: main exploit logic; argument parsing, DLL generation, malicious theme/themepack creation, SMB server startup, and SMB request manipulation. - rev_shell_template.cpp: optional payload template implementing VerifyThemeVersion and reverse shell callback. - theme_template.theme: malicious theme template containing attacker-controlled UNC path. - README.md: usage instructions and notes about supplying a custom DLL. - requirements.txt: dependencies (cabarchive, impacket). This is not merely a detector or demonstration artifact; it is an operational exploit PoC that automates delivery and includes a working payload template. The primary attack vectors are file-based delivery (user opens/applies theme/themepack) and network-based SMB hosting/callback.
This repository contains a single Metasploit module that exploits CVE-2023-38146 (ThemeBleed), a vulnerability in Windows 11 theme handling. The exploit abuses a time-of-check to time-of-use (TOCTOU) flaw in the way Windows loads .msstyles files and their associated DLLs. By serving a legitimate, signed DLL for signature verification and then swapping it for a malicious DLL at execution time via a controlled SMB share, the attacker can achieve arbitrary code execution on the victim's system. The module sets up a malicious SMB server, generates a theme file referencing the attacker's share, and delivers a payload DLL when the victim loads the theme. The only file in the repository is a Ruby script designed for the Metasploit framework, and it leverages Metasploit's payload generation and SMB server capabilities. The exploit targets unpatched Windows 11 systems and requires the victim to load a specially crafted theme file.
This repository is a proof-of-concept exploit for CVE-2023-38146 (ThemeBleed), a vulnerability in Windows 11 theme handling. The exploit consists of a Python script (themebleed.py) that sets up a malicious SMB server and generates a crafted Windows theme file (.theme or .themepack). The theme file references a DLL (Aero.msstyles_vrf_evil.dll) hosted on the attacker's SMB share. When a victim opens the malicious theme file, Windows connects to the attacker's SMB server and loads the DLL, which contains a reverse shell payload (written in C++ in rev_shell_template.cpp). The payload connects back to the attacker's specified IP and port, granting remote shell access. The repository includes templates for the theme file and the reverse shell DLL, as well as instructions for use. The exploit requires the attacker to run the SMB server and deliver the theme file to the victim. The main entry point is themebleed.py, which automates the SMB server setup and file generation. The exploit is operational and demonstrates remote code execution via a user interaction vector (opening a theme file) and network-based delivery (SMB).
This repository is a proof-of-concept (PoC) exploit for CVE-2023-38146, also known as 'ThemeBleed', affecting Microsoft Windows. The exploit demonstrates how a malicious .theme or .themepack file can be crafted to reference a remote SMB server controlled by the attacker. The repository contains a C# project that can: - Run an SMB server that serves three files (stage_1, stage_2, stage_3) to the victim. - Generate .theme and .themepack files that reference the attacker's SMB share (e.g., \\<host>\test\Aero.msstyles). The exploit flow is as follows: 1. The attacker runs the SMB server (using the 'server' command), which serves the required files. 2. The attacker generates a .theme or .themepack file referencing their SMB server and delivers it to the victim. 3. When the victim opens the malicious theme file, Windows connects to the attacker's SMB share and requests the files in a specific order. 4. The server responds with a specially crafted msstyles file (stage_1), a valid signed msstyles file (stage_2), and finally a DLL (stage_3) that is loaded and executed by the victim's system. The provided DLL payload (stage_3) in the PoC simply launches calc.exe, but this can be replaced with any DLL containing a 'VerifyThemeVersion' export for arbitrary code execution. The main code files are in C# (Program.cs, NTFilteredFileSystem.cs), and the project is structured as a Visual Studio solution. The exploit is a PoC and not weaponized, but demonstrates the full attack chain for ThemeBleed.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.