EIP-2026-118525

PRE-CVE

ExcelOCX ActiveX 3.2 - Download File Insecure Method

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118525. PoCs published by Alfons Luja.

AI-analyzed exploit summary This exploit targets Excel Viewer OCX 3.2, leveraging arbitrary file download and overwrite vulnerabilities via the `HttpDownloadFile` and `Save` methods. It demonstrates unsafe ActiveX control usage despite being marked as safe for scripting.

Description

ExcelOCX ActiveX 3.2 - Download File Insecure Method

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alfons Luja · htmlremotewindows
https://www.exploit-db.com/exploits/7739

This exploit targets Excel Viewer OCX 3.2, leveraging arbitrary file download and overwrite vulnerabilities via the `HttpDownloadFile` and `Save` methods. It demonstrates unsafe ActiveX control usage despite being marked as safe for scripting.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Excel Viewer OCX 3.2
No auth needed
Prerequisites: Victim must visit a malicious webpage using a browser with the vulnerable ActiveX control installed (e.g., IE6 or Avant Browser 11.7.21)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026