EIP-2026-119146

PRE-CVE

Skype - URI Handler Input Validation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119146. PoCs published by Paul Craig.

AI-analyzed exploit summary The writeup details a vulnerability in the Windows Skype client's URI handler, allowing command line argument injection via raw binary bytes to override the Datapath and potentially exfiltrate user data to a remote SMB share. It includes technical details on the exploitation method and mitigation steps.

Description

Skype - URI Handler Input Validation

Exploits (1)

exploitdb WRITEUP VERIFIED
by Paul Craig · textremotewindows
https://www.exploit-db.com/exploits/11694

The writeup details a vulnerability in the Windows Skype client's URI handler, allowing command line argument injection via raw binary bytes to override the Datapath and potentially exfiltrate user data to a remote SMB share. It includes technical details on the exploitation method and mitigation steps.

Classification
Writeup 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Skype for Windows (versions prior to 4.2 hotfix #1)
No auth needed
Prerequisites: Victim interaction (clicking a malformed Skype link) · Access to a remote SMB share
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026