Enriched mode implements an extension command to the text/enriched format called "x-display", which stores "display" text properties. It's possible to use this extension command to transparently execute arbitrary code in an Emacs process that opens a text/enriched file.
Upstream issue:
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=28350
Upstream patch:
https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-25&id=9ad0fcc54442a9a01d41be19880250783426db70
References:
http://seclists.org/oss-sec/2017/q3/422