EIP-2026-115909

PRE-CVE

NCTVideoStudio ActiveX DLLs 1.6 - Remote Heap Overflow (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115909. PoCs published by Stack.

AI-analyzed exploit summary This is a functional proof-of-concept exploit for a heap overflow vulnerability in NCTVideoStudio ActiveX DLLs Version 1.6. The exploit uses a crafted string to trigger a heap overflow in the 'CreateFile' method of the NCTAudioFile2Lib.AudioFile2 ActiveX control, leading to a crash at address 7C97DF51 in ntdll.

Description

NCTVideoStudio ActiveX DLLs 1.6 - Remote Heap Overflow (PoC)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · htmldoswindows
https://www.exploit-db.com/exploits/7882

This is a functional proof-of-concept exploit for a heap overflow vulnerability in NCTVideoStudio ActiveX DLLs Version 1.6. The exploit uses a crafted string to trigger a heap overflow in the 'CreateFile' method of the NCTAudioFile2Lib.AudioFile2 ActiveX control, leading to a crash at address 7C97DF51 in ntdll.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: NCTVideoStudio ActiveX DLLs Version 1.6
No auth needed
Prerequisites: Target system must have NCTVideoStudio ActiveX DLLs Version 1.6 installed · ActiveX controls must be enabled in the browser
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026