EIP-2026-117563
PRE-CVEMicrosoft Windows CONTACT - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117563. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This advisory details a vulnerability in Microsoft Windows .CONTACT files where the <c:Url> node can be manipulated to execute arbitrary code instead of navigating to a website. The exploit leverages directory traversal and file extension manipulation to deceive users into running executables disguised as web links.
Description
Microsoft Windows CONTACT - Remote Code Execution
Exploits (1)
This advisory details a vulnerability in Microsoft Windows .CONTACT files where the <c:Url> node can be manipulated to execute arbitrary code instead of navigating to a website. The exploit leverages directory traversal and file extension manipulation to deceive users into running executables disguised as web links.