EIP-2026-117122

PRE-CVE

Elantech-Smart Pad 11.9.0.0 - Unquoted Service Path Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117122. PoCs published by zaeek.

AI-analyzed exploit summary This exploit demonstrates an unquoted service path vulnerability in Elantech Smart-Pad Service, allowing local privilege escalation by placing a malicious executable in the service path. The service will execute the malicious file with elevated privileges upon restart or system reboot.

Description

Elantech-Smart Pad 11.9.0.0 - Unquoted Service Path Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by zaeek · textlocalwindows
https://www.exploit-db.com/exploits/40425

This exploit demonstrates an unquoted service path vulnerability in Elantech Smart-Pad Service, allowing local privilege escalation by placing a malicious executable in the service path. The service will execute the malicious file with elevated privileges upon restart or system reboot.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Elantech Smart-Pad Service 11.9.0.0
Auth required
Prerequisites: Local access to the system · Ability to write to the service path directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026