EIP-2026-117570
PRE-CVEMicrosoft Windows Media Center 6.1.7600 - 'ehshell.exe' XML External Entity Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-117570. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) vulnerability in Windows Media Center (ehshell.exe) that allows remote file disclosure. The PoC involves crafting a malicious .mcl file with an external DTD to exfiltrate files like msdfmap.ini when opened by the victim.
Description
Microsoft Windows Media Center 6.1.7600 - 'ehshell.exe' XML External Entity Injection
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) vulnerability in Windows Media Center (ehshell.exe) that allows remote file disclosure. The PoC involves crafting a malicious .mcl file with an external DTD to exfiltrate files like msdfmap.ini when opened by the victim.