EIP-2026-118196
PRE-CVEZemana AntiLogger 'AntiLog32.sys' 1.5.2.755 - Local Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118196. PoCs published by th_decoder.
AI-analyzed exploit summary This exploit demonstrates a local privilege escalation vulnerability in Zemana AntiLogger's AntiLog32.sys driver by abusing an insecure DeviceIoControl request (IOCTL 0x8000201C) to impersonate a system process (PID 4) and elevate privileges.
Description
Zemana AntiLogger 'AntiLog32.sys' 1.5.2.755 - Local Privilege Escalation
Exploits (1)
exploitdb
WORKING POC
by th_decoder · textlocalwindows
https://www.exploit-db.com/exploits/14491
This exploit demonstrates a local privilege escalation vulnerability in Zemana AntiLogger's AntiLog32.sys driver by abusing an insecure DeviceIoControl request (IOCTL 0x8000201C) to impersonate a system process (PID 4) and elevate privileges.
Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target:
Zemana AntiLogger <=1.9.2.2.206 (AntiLog32.sys <= 1.5.2.755)
No auth needed
Prerequisites:
Local access to the system · Zemana AntiLogger installed with vulnerable driver
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026