EIP-2026-119133
PRE-CVESIEMENS Solid Edge ST4/ST5 WebPartHelper - ActiveX RFMSsvs!JShellExecuteEx Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119133. PoCs published by rgod.
AI-analyzed exploit summary This exploit leverages an unsafe ActiveX control in Siemens Solid Edge ST4/ST5 to execute arbitrary commands via the OpenInEditor() method, which calls ShellExecuteExW() with attacker-controlled input. The PoC demonstrates RCE by launching calc.exe or a remote .jar file to bypass confirmation prompts.
Description
SIEMENS Solid Edge ST4/ST5 WebPartHelper - ActiveX RFMSsvs!JShellExecuteEx Remote Code Execution
Exploits (1)
This exploit leverages an unsafe ActiveX control in Siemens Solid Edge ST4/ST5 to execute arbitrary commands via the OpenInEditor() method, which calls ShellExecuteExW() with attacker-controlled input. The PoC demonstrates RCE by launching calc.exe or a remote .jar file to bypass confirmation prompts.