EIP-2026-118010
PRE-CVETomabo MP4 Player 3.11.3 - '.m3u' Local Buffer Overflow (SEH)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118010. PoCs published by Saeid Atabaki.
AI-analyzed exploit summary This exploit demonstrates a SEH buffer overflow vulnerability in Tomabo MP4 Player 3.11.3 via a crafted .m3u file. It includes a bind shell payload for remote code execution on Windows XP SP3.
Description
Tomabo MP4 Player 3.11.3 - '.m3u' Local Buffer Overflow (SEH)
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Saeid Atabaki · pythonlocalwindows
https://www.exploit-db.com/exploits/37730
This exploit demonstrates a SEH buffer overflow vulnerability in Tomabo MP4 Player 3.11.3 via a crafted .m3u file. It includes a bind shell payload for remote code execution on Windows XP SP3.
Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
Tomabo MP4 Player 3.11.3
No auth needed
Prerequisites:
Victim must open the malicious .m3u file in Tomabo MP4 Player
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026