EIP-2026-118801

PRE-CVE

Microsoft Internet Explorer - 'mshtml.dll' CSS Parsing Buffer Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118801. PoCs published by Arabteam2000.

AI-analyzed exploit summary This exploit generates a malicious CSS file that triggers a buffer overflow in Internet Explorer's mshtml.dll when parsed, leading to arbitrary code execution via embedded shellcode. The shellcode displays a MessageBox as a proof of concept.

Description

Microsoft Internet Explorer - 'mshtml.dll' CSS Parsing Buffer Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by Arabteam2000 · c++remotewindows
https://www.exploit-db.com/exploits/868

This exploit generates a malicious CSS file that triggers a buffer overflow in Internet Explorer's mshtml.dll when parsed, leading to arbitrary code execution via embedded shellcode. The shellcode displays a MessageBox as a proof of concept.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Internet Explorer (mshtml.dll)
No auth needed
Prerequisites: Victim must load a crafted HTML file referencing the malicious CSS
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026