EIP-2026-117562
PRE-CVEMicrosoft Windows CONTACT - HTML Injection / Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117562. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This advisory details a vulnerability in Microsoft Windows .CONTACT files where HTML injection in the E-mail field allows arbitrary code execution via crafted 'mailto:' links. The exploit leverages lack of input validation to execute local executables when the user clicks the link.
Description
Microsoft Windows CONTACT - HTML Injection / Remote Code Execution
Exploits (1)
This advisory details a vulnerability in Microsoft Windows .CONTACT files where HTML injection in the E-mail field allows arbitrary code execution via crafted 'mailto:' links. The exploit leverages lack of input validation to execute local executables when the user clicks the link.