EIP-2026-117477
PRE-CVEMicrosoft Authorization Manager 6.1.7601 - 'azman' XML External Entity Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117477. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XXE (XML External Entity) vulnerability in Microsoft Authorization Manager (azman.msc) via msxml3.dll, allowing file exfiltration by tricking a user into opening a malicious XML file. The PoC includes steps to create an evil XML file and a DTD payload to steal files like system.ini.
Description
Microsoft Authorization Manager 6.1.7601 - 'azman' XML External Entity Injection
Exploits (1)
This exploit demonstrates an XXE (XML External Entity) vulnerability in Microsoft Authorization Manager (azman.msc) via msxml3.dll, allowing file exfiltration by tricking a user into opening a malicious XML file. The PoC includes steps to create an evil XML file and a DTD payload to steal files like system.ini.