EIP-2026-103985
PRE-CVEMicrosoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103985. PoCs published by nu11secur1ty.
AI-analyzed exploit summary The exploit leverages a spoofing vulnerability in Microsoft OneNote by embedding a VBA macro that executes a command to download and run a malicious script. The script deletes files in the user's IMPORTANT directory, demonstrating arbitrary code execution via a crafted OneNote file.
Description
Microsoft OneNote (Version 2305 Build 16.0.16501.20074) 64-bit - Spoofing
Exploits (1)
The exploit leverages a spoofing vulnerability in Microsoft OneNote by embedding a VBA macro that executes a command to download and run a malicious script. The script deletes files in the user's IMPORTANT directory, demonstrating arbitrary code execution via a crafted OneNote file.