EIP-2026-118890

PRE-CVE

Microsoft Windows VCF or Contact' File - URL Manipulation-Spoof Arbitrary Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-118890. PoCs published by Eduardo Braun Prado.

AI-analyzed exploit summary This is a writeup describing a vulnerability in Microsoft Windows involving VCF or Contact file URL manipulation leading to arbitrary code execution. The actual exploit is referenced as a separate downloadable file.

Description

Microsoft Windows VCF or Contact' File - URL Manipulation-Spoof Arbitrary Code Execution

Exploits (1)

exploitdb WRITEUP
by Eduardo Braun Prado · textremotewindows
https://www.exploit-db.com/exploits/46220

This is a writeup describing a vulnerability in Microsoft Windows involving VCF or Contact file URL manipulation leading to arbitrary code execution. The actual exploit is referenced as a separate downloadable file.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Windows 7 SP1, 8.1, 10 v.1809
No auth needed
Prerequisites: Victim interaction to open a malicious VCF file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026