EIP-2026-117130
PRE-CVEEnhanced Mitigation Experience Toolkit (EMET) - XML External Entity Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117130. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft EMET, allowing local file exfiltration to a remote server via a crafted .config file. The PoC includes a DTD file and a malicious XML payload that reads C:\Windows\system.ini and sends its contents to an attacker-controlled server.
Description
Enhanced Mitigation Experience Toolkit (EMET) - XML External Entity Injection
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft EMET, allowing local file exfiltration to a remote server via a crafted .config file. The PoC includes a DTD file and a malicious XML payload that reads C:\Windows\system.ini and sends its contents to an attacker-controlled server.