EIP-2026-117478
PRE-CVEMicrosoft Baseline Security Analyzer 2.3 - XML External Entity Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117478. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft Baseline Security Analyzer 2.3, allowing local file exfiltration or NTLM hash theft via a crafted .mbsa file. The PoC includes both file exfiltration and forced authentication techniques.
Description
Microsoft Baseline Security Analyzer 2.3 - XML External Entity Injection
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft Baseline Security Analyzer 2.3, allowing local file exfiltration or NTLM hash theft via a crafted .mbsa file. The PoC includes both file exfiltration and forced authentication techniques.