Vulnerability & Exploit Database

Back to search

Windows Gather Microsoft Office Word UNC Path Injector

This module modifies a remote .docx file that will, upon opening, submit stored netNTLM credentials to a remote host. Verified to work with Microsoft Word 2003, 2007, 2010, and 2013. In order to get the hashes the auxiliary/server/capture/smb module can be used.

Free Metasploit Download

Get your copy of the world's leading penetration testing tool

 Download Now

Module Name



  • SphaZ <cyberphaz [at]>



  • windows



Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use post/windows/gather/word_unc_injector msf post(word_unc_injector) > sessions ...sessions... msf post(word_unc_injector) > set SESSION <session-id> msf post(word_unc_injector) > show options and set options... msf post(word_unc_injector) > run