EIP-2026-115009

PRE-CVE

Browse3D 3.5 - '.sfs' Local Buffer Overflow (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115009. PoCs published by Houssamix.

AI-analyzed exploit summary This Perl script demonstrates a local buffer overflow vulnerability in Browse3D v3.5 by creating a malformed .sfs file that triggers an access violation when opened. The PoC uses a NOP sled and a hardcoded address (0x41414141) to crash the application, indicating potential for arbitrary code execution.

Description

Browse3D 3.5 - '.sfs' Local Buffer Overflow (PoC)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Houssamix · perldoswindows
https://www.exploit-db.com/exploits/7721

This Perl script demonstrates a local buffer overflow vulnerability in Browse3D v3.5 by creating a malformed .sfs file that triggers an access violation when opened. The PoC uses a NOP sled and a hardcoded address (0x41414141) to crash the application, indicating potential for arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Browse3D v3.5
No auth needed
Prerequisites: Victim must open the malformed .sfs file in Browse3D v3.5
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026