EIP-2026-115541

PRE-CVE

LanWhoIs.exe 1.0.1.120 - Stack Buffer Overflow (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115541. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates a local buffer overflow vulnerability in LanWhoIs.exe 1.0.1.120 by injecting a malicious payload into the QueryString node of the whois_result.xml file, overwriting SEH handlers and controlling EIP at approximately 676 bytes.

Description

LanWhoIs.exe 1.0.1.120 - Stack Buffer Overflow (PoC)

Exploits (1)

exploitdb WORKING POC
by hyp3rlinx · pythondoswindows
https://www.exploit-db.com/exploits/38404

This exploit demonstrates a local buffer overflow vulnerability in LanWhoIs.exe 1.0.1.120 by injecting a malicious payload into the QueryString node of the whois_result.xml file, overwriting SEH handlers and controlling EIP at approximately 676 bytes.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: LanWhoIs.exe 1.0.1.120
No auth needed
Prerequisites: LanWhoIs installed in a writable directory (e.g., C:\), non-admin user access to modify whois_result.xml
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026