EIP-2026-115541
PRE-CVELanWhoIs.exe 1.0.1.120 - Stack Buffer Overflow (PoC)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-115541. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a local buffer overflow vulnerability in LanWhoIs.exe 1.0.1.120 by injecting a malicious payload into the QueryString node of the whois_result.xml file, overwriting SEH handlers and controlling EIP at approximately 676 bytes.
Description
LanWhoIs.exe 1.0.1.120 - Stack Buffer Overflow (PoC)
Exploits (1)
exploitdb
WORKING POC
by hyp3rlinx · pythondoswindows
https://www.exploit-db.com/exploits/38404
This exploit demonstrates a local buffer overflow vulnerability in LanWhoIs.exe 1.0.1.120 by injecting a malicious payload into the QueryString node of the whois_result.xml file, overwriting SEH handlers and controlling EIP at approximately 676 bytes.
Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target:
LanWhoIs.exe 1.0.1.120
No auth needed
Prerequisites:
LanWhoIs installed in a writable directory (e.g., C:\), non-admin user access to modify whois_result.xml
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026