EIP-2026-116183

PRE-CVE

RichFX Basic Player 1.1 - ActiveX Control Multiple Buffer Overflow Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116183. PoCs published by Elazar Broad.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the RichFX Basic Player ActiveX Control by supplying an excessively long string to the 'DoInstall' and 'QueryComponents' methods, potentially leading to arbitrary code execution in the context of Internet Explorer.

Description

RichFX Basic Player 1.1 - ActiveX Control Multiple Buffer Overflow Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Elazar Broad · htmldoswindows
https://www.exploit-db.com/exploits/30805

This exploit targets a buffer overflow vulnerability in the RichFX Basic Player ActiveX Control by supplying an excessively long string to the 'DoInstall' and 'QueryComponents' methods, potentially leading to arbitrary code execution in the context of Internet Explorer.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: RichFX Basic Player ActiveX Control (installed with RealNetworks RealPlayer)
No auth needed
Prerequisites: Victim must have the vulnerable ActiveX control installed · Victim must visit a malicious webpage or open a malicious HTML file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026