How does the attack work?
1️⃣ A crafted RTF file is sent via email.
2️⃣ Victim previews the email in Outlook—no clicks
needed.
3️⃣ OLE object triggers the double-free, enabling arbitrary code execution.
4️⃣ Attacker can install malware, steal data, or escalate privileges.