EIP-2026-116775
PRE-CVEAlreader 2.5 .fb2 - Based Stack Overflow (SEH) (ASLR + DEP Bypass)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-116775. PoCs published by g00dv1n.
AI-analyzed exploit summary This exploit leverages a SEH-based stack overflow in Alreader 2.5 via a malformed .fb2 file, bypassing ASLR and DEP using ROP chains to execute arbitrary shellcode (e.g., launching Calc.exe). The payload is crafted in UTF-16 to exploit WCHAR handling and includes version-specific ROP chains for both Russian and English builds.
Description
Alreader 2.5 .fb2 - Based Stack Overflow (SEH) (ASLR + DEP Bypass)
Exploits (1)
This exploit leverages a SEH-based stack overflow in Alreader 2.5 via a malformed .fb2 file, bypassing ASLR and DEP using ROP chains to execute arbitrary shellcode (e.g., launching Calc.exe). The payload is crafted in UTF-16 to exploit WCHAR handling and includes version-specific ROP chains for both Russian and English builds.