EIP-2026-115547

PRE-CVE

LeadTools 11.5.0.9 - 'ltlst11n.ocx' Insert() Access Violation Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115547. PoCs published by Matthew Bergin.

AI-analyzed exploit summary This exploit targets a vulnerability in the LEADImgListLib.LEADImgList ActiveX control (ltlst11n.ocx) by passing malformed arguments to the 'Insert' method, leading to an access violation and potential remote code execution. The PoC demonstrates the crash via a crafted HTML page with VBScript.

Description

LeadTools 11.5.0.9 - 'ltlst11n.ocx' Insert() Access Violation Denial of Service

Exploits (1)

exploitdb WORKING POC
by Matthew Bergin · htmldoswindows
https://www.exploit-db.com/exploits/15433

This exploit targets a vulnerability in the LEADImgListLib.LEADImgList ActiveX control (ltlst11n.ocx) by passing malformed arguments to the 'Insert' method, leading to an access violation and potential remote code execution. The PoC demonstrates the crash via a crafted HTML page with VBScript.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: LEADImgListLib.LEADImgList ActiveX control (ltlst11n.ocx)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · Target system must have the vulnerable ActiveX control installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026