EIP-2026-116290

PRE-CVE

SPlayer XvidDecoder 3.3 - ActiveX Remote Execution (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116290. PoCs published by superli.

AI-analyzed exploit summary This exploit leverages a vulnerable ActiveX control (CLSID: {E5960BC4-A76B-4211-BEEC-9AEE2AF8AAE6}) to trigger a use-after-free or memory corruption vulnerability in Internet Explorer 6 on Windows XP SP3. The minimal HTML object tag is sufficient to demonstrate the vulnerability when rendered in the target environment.

Description

SPlayer XvidDecoder 3.3 - ActiveX Remote Execution (PoC)

Exploits (1)

exploitdb WORKING POC VERIFIED
by superli · htmldoswindows
https://www.exploit-db.com/exploits/11065

This exploit leverages a vulnerable ActiveX control (CLSID: {E5960BC4-A76B-4211-BEEC-9AEE2AF8AAE6}) to trigger a use-after-free or memory corruption vulnerability in Internet Explorer 6 on Windows XP SP3. The minimal HTML object tag is sufficient to demonstrate the vulnerability when rendered in the target environment.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Internet Explorer 6 on Windows XP SP3
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer 6 on Windows XP SP3
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026