EIP-2026-116768

PRE-CVE

ALLPlayer 7.4 - Local Buffer Overflow (SEH Unicode)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116768. PoCs published by f3ci.

AI-analyzed exploit summary This exploit targets a SEH-based buffer overflow in ALL Player v7.4, using a Unicode-encoded shellcode payload to achieve remote code execution via a crafted .m3u file. The exploit leverages a venetian technique to bypass Unicode restrictions and deliver a bind shell on port 4444.

Description

ALLPlayer 7.4 - Local Buffer Overflow (SEH Unicode)

Exploits (1)

exploitdb WORKING POC VERIFIED
by f3ci · pythonlocalwindows
https://www.exploit-db.com/exploits/42455

This exploit targets a SEH-based buffer overflow in ALL Player v7.4, using a Unicode-encoded shellcode payload to achieve remote code execution via a crafted .m3u file. The exploit leverages a venetian technique to bypass Unicode restrictions and deliver a bind shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: ALL Player v7.4
No auth needed
Prerequisites: Victim must open the malicious .m3u file in ALL Player v7.4
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026