EIP-2026-117558

PRE-CVE

Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117558. PoCs published by Moein Shahabi.

AI-analyzed exploit summary This exploit demonstrates a DLL hijacking vulnerability in Windows 11 by leveraging the HelpPane object to force-load a malicious 'apds.dll'. The provided code includes a DLL with exported functions that proxy legitimate exports while executing arbitrary code (e.g., a MessageBox).

Description

Microsoft Windows 11 - 'apds.dll' DLL hijacking (Forced)

Exploits (1)

exploitdb WORKING POC
by Moein Shahabi · textlocalwindows
https://www.exploit-db.com/exploits/51733

This exploit demonstrates a DLL hijacking vulnerability in Windows 11 by leveraging the HelpPane object to force-load a malicious 'apds.dll'. The provided code includes a DLL with exported functions that proxy legitimate exports while executing arbitrary code (e.g., a MessageBox).

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows 11 Pro 10.0.22621
No auth needed
Prerequisites: Ability to place a malicious DLL in 'C:\Windows\' · Execution of the HelpPane object via PowerShell or similar
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026