EIP-2026-103985

PRE-CVE

Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103985. PoCs published by nu11secur1ty.

AI-analyzed exploit summary The exploit leverages a spoofing vulnerability in Microsoft OneNote by embedding a VBA macro that executes a command to download and run a malicious script. The script deletes files in the user's IMPORTANT directory, demonstrating arbitrary code execution via a crafted OneNote file.

Description

Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing

Exploits (1)

exploitdb WORKING POC
by nu11secur1ty · textremotemultiple
https://www.exploit-db.com/exploits/51538

The exploit leverages a spoofing vulnerability in Microsoft OneNote by embedding a VBA macro that executes a command to download and run a malicious script. The script deletes files in the user's IMPORTANT directory, demonstrating arbitrary code execution via a crafted OneNote file.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit
No auth needed
Prerequisites: Victim must open a malicious OneNote file · Macros must be enabled or user must be tricked into enabling them
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026