EIP-2026-117223
PRE-CVEFunduc Search and Replace - Compressed File Local Buffer Overflow
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117223. PoCs published by ATmaCA.
AI-analyzed exploit summary This exploit generates a maliciously crafted ZIP file to trigger a local buffer overflow in Search and Replace 5.0 and prior versions. The overflow occurs due to an overly long filename in the ZIP structure, overwriting the EIP with a placeholder (0x41414141).
Description
Funduc Search and Replace - Compressed File Local Buffer Overflow
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by ATmaCA · clocalwindows
https://www.exploit-db.com/exploits/769
This exploit generates a maliciously crafted ZIP file to trigger a local buffer overflow in Search and Replace 5.0 and prior versions. The overflow occurs due to an overly long filename in the ZIP structure, overwriting the EIP with a placeholder (0x41414141).
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Search and Replace 5.0 and prior versions
No auth needed
Prerequisites:
Ability to deliver the crafted ZIP file to the target system
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026