EIP-2026-115670

PRE-CVE

Microsoft Internet Explorer - Overly Trusted Location Cache

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115670. PoCs published by anonymous.

AI-analyzed exploit summary This exploit targets a vulnerability in Internet Explorer by manipulating the `document.execCommand('Refresh')` and `createPopup()` methods to inject JavaScript into a new window context. It leverages a timing-based approach to bypass security restrictions and execute arbitrary code.

Description

Microsoft Internet Explorer - Overly Trusted Location Cache

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · htmldoswindows
https://www.exploit-db.com/exploits/354

This exploit targets a vulnerability in Internet Explorer by manipulating the `document.execCommand('Refresh')` and `createPopup()` methods to inject JavaScript into a new window context. It leverages a timing-based approach to bypass security restrictions and execute arbitrary code.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Racy
Target: Internet Explorer (unspecified version, likely older versions)
No auth needed
Prerequisites: Victim must open the malicious HTML file in a vulnerable version of Internet Explorer
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026