EIP-2026-118524

PRE-CVE

Excel Viewer OCX 3.2 - Remote Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118524. PoCs published by Stack.

AI-analyzed exploit summary This HTML-based exploit leverages the Excel Viewer OCX 3.2 ActiveX control (CLSID: {18A295DA-088E-42D1-BE31-5028D7F9B965}) to execute a remote file via the OpenWebFile method. The exploit is triggered by a button click, which fetches and executes a malicious payload (calc.exe) from a remote server.

Description

Excel Viewer OCX 3.2 - Remote Command Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stack · htmlremotewindows
https://www.exploit-db.com/exploits/7763

This HTML-based exploit leverages the Excel Viewer OCX 3.2 ActiveX control (CLSID: {18A295DA-088E-42D1-BE31-5028D7F9B965}) to execute a remote file via the OpenWebFile method. The exploit is triggered by a button click, which fetches and executes a malicious payload (calc.exe) from a remote server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Excel Viewer OCX 3.2
No auth needed
Prerequisites: Victim must open the HTML file in a browser with ActiveX enabled · Excel Viewer OCX 3.2 must be installed and registered
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026