EIP-2026-117141

PRE-CVE

ESTsoft ALYac Anti-Virus 1.5 < 5.0.1.2 - Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117141. PoCs published by MJ0011.

AI-analyzed exploit summary This exploit targets a local kernel mode privilege escalation vulnerability in ESTsoft ALYac Anti-Virus 1.5 by overwriting the system service descriptor table entry via the AYDrvNT.sys driver. It includes shellcode to display a success message on the screen using VGA mode functions.

Description

ESTsoft ALYac Anti-Virus 1.5 < 5.0.1.2 - Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by MJ0011 · textlocalwindows
https://www.exploit-db.com/exploits/15763

This exploit targets a local kernel mode privilege escalation vulnerability in ESTsoft ALYac Anti-Virus 1.5 by overwriting the system service descriptor table entry via the AYDrvNT.sys driver. It includes shellcode to display a success message on the screen using VGA mode functions.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ESTsoft ALYac Anti-Virus 1.5 with AYDrvNT.sys <= 5.0.1.2
No auth needed
Prerequisites: Local access to the system · Presence of vulnerable AYDrvNT.sys driver
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026