EIP-2026-119049

PRE-CVE

PowerPoint Viewer OCX 3.1 - Remote Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119049. PoCs published by Cyber-Zone.

AI-analyzed exploit summary This exploit leverages a vulnerability in PowerPoint Viewer OCX v3.1 to execute arbitrary files remotely via the OpenWebFile method. The HTML page embeds an ActiveX object and triggers file execution upon button click.

Description

PowerPoint Viewer OCX 3.1 - Remote Command Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cyber-Zone · htmlremotewindows
https://www.exploit-db.com/exploits/7755

This exploit leverages a vulnerability in PowerPoint Viewer OCX v3.1 to execute arbitrary files remotely via the OpenWebFile method. The HTML page embeds an ActiveX object and triggers file execution upon button click.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PowerPoint Viewer OCX v3.1
No auth needed
Prerequisites: Victim must open the malicious HTML file in a vulnerable environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026