EIP-2026-118764
PRE-CVEMcAfee SaaS MyCioScan ShowReport - Remote Command Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-118764. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a vulnerability in McAfee SaaS MyCioScan's ActiveX component (myCIOScn.dll) via the ShowReport() function, which fails to validate the FileName argument, allowing arbitrary command execution via ShellExecuteW(). It uses a WebDAV server to deliver a malicious VBS payload.
Description
McAfee SaaS MyCioScan ShowReport - Remote Command Execution (Metasploit)
Exploits (1)
This Metasploit module exploits a vulnerability in McAfee SaaS MyCioScan's ActiveX component (myCIOScn.dll) via the ShowReport() function, which fails to validate the FileName argument, allowing arbitrary command execution via ShellExecuteW(). It uses a WebDAV server to deliver a malicious VBS payload.