EIP-2026-116806
PRE-CVEAppLocker - Execution Prevention Bypass (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-116806. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module bypasses AppLocker by generating a .NET service executable and using InstallUtil to execute a payload. It compiles a C# source file into an executable and leverages InstallUtil to run it, bypassing AppLocker restrictions.
Description
AppLocker - Execution Prevention Bypass (Metasploit)
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/39523
This Metasploit module bypasses AppLocker by generating a .NET service executable and using InstallUtil to execute a payload. It compiles a C# source file into an executable and leverages InstallUtil to run it, bypassing AppLocker restrictions.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Windows with AppLocker
Auth required
Prerequisites:
Meterpreter session on the target · .NET Framework installed
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026