EIP-2026-118196

PRE-CVE

Zemana AntiLogger 'AntiLog32.sys' 1.5.2.755 - Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118196. PoCs published by th_decoder.

AI-analyzed exploit summary This exploit demonstrates a local privilege escalation vulnerability in Zemana AntiLogger's AntiLog32.sys driver by abusing an insecure DeviceIoControl request (IOCTL 0x8000201C) to impersonate a system process (PID 4) and elevate privileges.

Description

Zemana AntiLogger 'AntiLog32.sys' 1.5.2.755 - Local Privilege Escalation

Exploits (1)

exploitdb WORKING POC
by th_decoder · textlocalwindows
https://www.exploit-db.com/exploits/14491

This exploit demonstrates a local privilege escalation vulnerability in Zemana AntiLogger's AntiLog32.sys driver by abusing an insecure DeviceIoControl request (IOCTL 0x8000201C) to impersonate a system process (PID 4) and elevate privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Zemana AntiLogger <=1.9.2.2.206 (AntiLog32.sys <= 1.5.2.755)
No auth needed
Prerequisites: Local access to the system · Zemana AntiLogger installed with vulnerable driver
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026