EIP-2026-103245

PRE-CVE

Winace UnAce 2.2 - Command Line Argument Buffer Overflow (1)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103245. PoCs published by demz.

AI-analyzed exploit summary This is a functional local buffer overflow exploit for UnAce v2.2, leveraging an excessively long filename argument to overwrite the stack and execute arbitrary shellcode (setuid(0) + execve('/bin/sh')). The exploit targets a stack-based overflow in the UnAce utility.

Description

Winace UnAce 2.2 - Command Line Argument Buffer Overflow (1)

Exploits (1)

exploitdb WORKING POC VERIFIED
by demz · cremotelinux
https://www.exploit-db.com/exploits/23368

This is a functional local buffer overflow exploit for UnAce v2.2, leveraging an excessively long filename argument to overwrite the stack and execute arbitrary shellcode (setuid(0) + execve('/bin/sh')). The exploit targets a stack-based overflow in the UnAce utility.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: UnAce v2.2
No auth needed
Prerequisites: Local access to the target system · UnAce v2.2 installed · Ability to execute the vulnerable binary
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026