Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-117583. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit leverages a vulnerability in Microsoft Windows' handling of VCF (vCard) files, where a crafted URL field can trigger execution of a malicious CPL file. The PoC includes a compiled CPL file and a VCF file that, when opened, executes arbitrary code via a deceptive hyperlink.
Description
Microsoft Windows VCF - Remote Code Execution
Exploits (1)
This exploit leverages a vulnerability in Microsoft Windows' handling of VCF (vCard) files, where a crafted URL field can trigger execution of a malicious CPL file. The PoC includes a compiled CPL file and a VCF file that, when opened, executes arbitrary code via a deceptive hyperlink.