EIP-2026-117653

PRE-CVE

Multiples Nexon Games - Unquoted Path Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117653. PoCs published by Cyril Vallicari.

AI-analyzed exploit summary This is a technical writeup describing an unquoted path vulnerability in multiple Nexon games (e.g., Dirty Bomb, Counter-Strike Nexon: Zombies) that allows local privilege escalation by exploiting improperly quoted paths in the BlackXcht.aes anti-cheat system. The PoC involves placing a malicious executable in the root of C: to achieve code execution with elevated privileges.

Description

Multiples Nexon Games - Unquoted Path Privilege Escalation

Exploits (1)

exploitdb WRITEUP
by Cyril Vallicari · textlocalwindows
https://www.exploit-db.com/exploits/39814

This is a technical writeup describing an unquoted path vulnerability in multiple Nexon games (e.g., Dirty Bomb, Counter-Strike Nexon: Zombies) that allows local privilege escalation by exploiting improperly quoted paths in the BlackXcht.aes anti-cheat system. The PoC involves placing a malicious executable in the root of C: to achieve code execution with elevated privileges.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Nexon Games (Dirty Bomb r56825 USA_EU, Counter-Strike Nexon: Zombies 0.0.18845.1)
Auth required
Prerequisites: Local access to the system · Ability to place an executable in C:\
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026