EIP-2026-118241

PRE-CVE

Advanced File Vault - 'eSellerateControl350.dll' ActiveX HeapSpray

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118241. PoCs published by ThE g0bL!N.

AI-analyzed exploit summary This is a heap spray exploit targeting a vulnerability in Advanced File Vault's eSellerateControl350.dll ActiveX control. It uses JavaScript to spray the heap with NOP sleds and shellcode, then triggers the vulnerability via the GetWebStoreURL method to achieve arbitrary code execution.

Description

Advanced File Vault - 'eSellerateControl350.dll' ActiveX HeapSpray

Exploits (1)

exploitdb WORKING POC VERIFIED
by ThE g0bL!N · htmlremotewindows
https://www.exploit-db.com/exploits/14580

This is a heap spray exploit targeting a vulnerability in Advanced File Vault's eSellerateControl350.dll ActiveX control. It uses JavaScript to spray the heap with NOP sleds and shellcode, then triggers the vulnerability via the GetWebStoreURL method to achieve arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Advanced File Vault (eSellerateControl350.dll)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · ActiveX control must be installed and enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026