EIP-2026-115544

PRE-CVE

LeadTools 11.5.0.9 - 'ltdlg11n.ocx' Bitmap Access Violation Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115544. PoCs published by Matthew Bergin.

AI-analyzed exploit summary This exploit targets a vulnerability in the LEADDlgLib.LEADDlg ActiveX control (ltdlg11n.ocx) by passing an invalid argument (-1) to the 'Bitmap' property, leading to an ACCESS_VIOLATION. The crash occurs due to a NULL pointer dereference when the code attempts to compare a value at address 0x00000000.

Description

LeadTools 11.5.0.9 - 'ltdlg11n.ocx' Bitmap Access Violation Denial of Service

Exploits (1)

exploitdb WORKING POC
by Matthew Bergin · htmldoswindows
https://www.exploit-db.com/exploits/15436

This exploit targets a vulnerability in the LEADDlgLib.LEADDlg ActiveX control (ltdlg11n.ocx) by passing an invalid argument (-1) to the 'Bitmap' property, leading to an ACCESS_VIOLATION. The crash occurs due to a NULL pointer dereference when the code attempts to compare a value at address 0x00000000.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: LEADDlgLib.LEADDlg ActiveX control (ltdlg11n.ocx) in Rational software
No auth needed
Prerequisites: Target system with the vulnerable LEADDlgLib.LEADDlg ActiveX control installed · Internet Explorer or a browser that supports ActiveX controls
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026