EIP-2026-118841

PRE-CVE

Microsoft Internet Explorer 6 - URL Local Resource Access

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118841. PoCs published by Rafel Ivgi The-Insider.

AI-analyzed exploit summary This exploit leverages a URL protocol handler weakness in Microsoft Internet Explorer to bypass security restrictions and execute arbitrary code via a crafted HTML page. It demonstrates how an attacker can inject malicious scripts to download and execute a payload from a remote share.

Description

Microsoft Internet Explorer 6 - URL Local Resource Access

Exploits (1)

exploitdb WORKING POC VERIFIED
by Rafel Ivgi The-Insider · textremotewindows
https://www.exploit-db.com/exploits/24174

This exploit leverages a URL protocol handler weakness in Microsoft Internet Explorer to bypass security restrictions and execute arbitrary code via a crafted HTML page. It demonstrates how an attacker can inject malicious scripts to download and execute a payload from a remote share.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer 6 SP1
No auth needed
Prerequisites: Victim must visit a malicious webpage · SMB share access for payload delivery
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026