CVE-2005-2694

WinAce 2.6.0.5 - Buffer Overflow via Long File Name in Temporary File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2005-2694. PoCs published by ATmaCA.

AI-analyzed exploit summary This exploit demonstrates a local buffer overflow in WinAce 2.6.0.5 by crafting a malicious .tmp file with an overly long filename, which overwrites the return address (EIP) to execute arbitrary code.

Description

Buffer overflow in WinAce 2.6.0.5, and possibly earlier versions, allows remote attackers to execute arbitrary code via a temporary (.tmp) file that contains an entry with a long file name.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ATmaCA · clocalwindows
https://www.exploit-db.com/exploits/1168

This exploit demonstrates a local buffer overflow in WinAce 2.6.0.5 by crafting a malicious .tmp file with an overly long filename, which overwrites the return address (EIP) to execute arbitrary code.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WinAce 2.6.0.5
No auth needed
Prerequisites: Local access to the target system · WinAce 2.6.0.5 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/21941
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=112447630109392&w=2

Scores

EPSS 0.0392
EPSS Percentile 89.0%

Details

Status published
Products (1)
winace/winace 2.6.0.5
Published Aug 26, 2005
Tracked Since Feb 18, 2026