EIP-2026-117570

PRE-CVE

Microsoft Windows Media Center 6.1.7600 - 'ehshell.exe' XML External Entity Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117570. PoCs published by hyp3rlinx.

AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) vulnerability in Windows Media Center (ehshell.exe) that allows remote file disclosure. The PoC involves crafting a malicious .mcl file with an external DTD to exfiltrate files like msdfmap.ini when opened by the victim.

Description

Microsoft Windows Media Center 6.1.7600 - 'ehshell.exe' XML External Entity Injection

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · textlocalwindows
https://www.exploit-db.com/exploits/40861

This exploit demonstrates an XML External Entity (XXE) vulnerability in Windows Media Center (ehshell.exe) that allows remote file disclosure. The PoC involves crafting a malicious .mcl file with an external DTD to exfiltrate files like msdfmap.ini when opened by the victim.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Windows Media Center (ehshell.exe) version 6.1.7600
No auth needed
Prerequisites: Victim must open a malicious .mcl file via remote share, USB, or a crafted windowsmediacenterweb link · Attacker must host a malicious DTD file and a listener to receive exfiltrated data
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026