EIP-2026-117495

PRE-CVE

Microsoft HTML Help Compiler 4.74.8702.0 - Local Overflow (SEH)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117495. PoCs published by St0rn.

AI-analyzed exploit summary This exploit leverages an SEH-based buffer overflow in Microsoft HTML Help Compiler (hhc.exe) to execute arbitrary shellcode, specifically launching calc.exe. The payload is crafted with a jump to bypass SEH and a null-free shellcode to avoid bad characters.

Description

Microsoft HTML Help Compiler 4.74.8702.0 - Local Overflow (SEH)

Exploits (1)

exploitdb WORKING POC
by St0rn · pythonlocalwindows
https://www.exploit-db.com/exploits/37771

This exploit leverages an SEH-based buffer overflow in Microsoft HTML Help Compiler (hhc.exe) to execute arbitrary shellcode, specifically launching calc.exe. The payload is crafted with a jump to bypass SEH and a null-free shellcode to avoid bad characters.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft HTML Help Workshop 4.74.8702.0
No auth needed
Prerequisites: hhc.exe installed on target system · ability to execute the script on the target
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026