EIP-2026-118645

PRE-CVE

HP Digital Imaging - 'hpodio08.dll' Insecure Method

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118645. PoCs published by ThE g0bL!N.

AI-analyzed exploit summary This exploit leverages an insecure method in HP Digital Imaging's hpodio08.dll to save an arbitrary file (dz.exe) to the system. The exploit uses a COM object with CLSID {697F5209-0494-11D6-A2B0-0060B0FBD872} to trigger the Save method, demonstrating a file write vulnerability.

Description

HP Digital Imaging - 'hpodio08.dll' Insecure Method

Exploits (1)

exploitdb WORKING POC
by ThE g0bL!N · htmlremotewindows
https://www.exploit-db.com/exploits/12367

This exploit leverages an insecure method in HP Digital Imaging's hpodio08.dll to save an arbitrary file (dz.exe) to the system. The exploit uses a COM object with CLSID {697F5209-0494-11D6-A2B0-0060B0FBD872} to trigger the Save method, demonstrating a file write vulnerability.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: HP Digital Imaging (hpodio08.dll)
No auth needed
Prerequisites: Victim must open the HTML file in a vulnerable environment (e.g., Windows XP SP2)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026