EIP-2026-117568
PRE-CVEMicrosoft Windows FxCop 10/12 - XML External Entity Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117568. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft Windows FxCop versions 10-12, allowing local file exfiltration or NTLM hash theft via a crafted .FxCop project file. The PoC includes a malicious DTD file hosted on an attacker-controlled server to exfiltrate file contents.
Description
Microsoft Windows FxCop 10/12 - XML External Entity Injection
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft Windows FxCop versions 10-12, allowing local file exfiltration or NTLM hash theft via a crafted .FxCop project file. The PoC includes a malicious DTD file hosted on an attacker-controlled server to exfiltrate file contents.