EIP-2026-117621

PRE-CVE

mks_vir 9b < 1.2.0.0b297 - 'mksmonen.sys' Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117621. PoCs published by NT Internals.

AI-analyzed exploit summary The provided content is a metadata description of an exploit for a local privilege escalation vulnerability in mks_vir 9 BETA, but it does not contain actual exploit code. Instead, it points to external download links (e.g., http://ntinternals.org/ntiadv0809/MksMonEn_Exp.zip), which is a common tactic in suspicious repositories.

Description

mks_vir 9b < 1.2.0.0b297 - 'mksmonen.sys' Local Privilege Escalation

Exploits (1)

exploitdb SUSPICIOUS VERIFIED
by NT Internals · textlocalwindows
https://www.exploit-db.com/exploits/8175

The provided content is a metadata description of an exploit for a local privilege escalation vulnerability in mks_vir 9 BETA, but it does not contain actual exploit code. Instead, it points to external download links (e.g., http://ntinternals.org/ntiadv0809/MksMonEn_Exp.zip), which is a common tactic in suspicious repositories.

Classification
Suspicious 90%
Attack Type
Lpe
Complexity
Theoretical
Reliability
Theoretical
Target: mks_vir 9 BETA < 1.2.0.0 - build 297 (mksmonen.sys driver)
No auth needed
Prerequisites: Local access to the target system · Presence of vulnerable mksmonen.sys driver
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026