EIP-2026-117512

PRE-CVE

Microsoft Windows - 'keybd_event' Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117512. PoCs published by Andrés Acunha.

AI-analyzed exploit summary This exploit leverages a Windows keybd_event validation vulnerability to send crafted keyboard inputs to a target process (e.g., explorer.exe), enabling local privilege escalation by simulating shortcut keys to execute arbitrary commands. It includes a bind shell on port 65535 for remote access post-exploitation.

Description

Microsoft Windows - 'keybd_event' Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Andrés Acunha · clocalwindows
https://www.exploit-db.com/exploits/1197

This exploit leverages a Windows keybd_event validation vulnerability to send crafted keyboard inputs to a target process (e.g., explorer.exe), enabling local privilege escalation by simulating shortcut keys to execute arbitrary commands. It includes a bind shell on port 65535 for remote access post-exploitation.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows 2000, XP, 2003
Auth required
Prerequisites: Access to a low-privileged shell or service with INTERACT_WITH_DESKTOP · Target process ID (e.g., explorer.exe)
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026