EIP-2026-119221

PRE-CVE

Trend Micro Internet Security Pro 2010 - ActiveX 'extSetOwner()' Remote Code Execution (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-119221. PoCs published by Abysssec.

AI-analyzed exploit summary This exploit targets a remote code execution vulnerability in Trend Micro Internet Security Pro 2010 via an ActiveX control (UfPBCtrl.DLL). It uses a heap spray technique to achieve reliable exploitation, leveraging a specific memory address in mshtml.dll to execute shellcode.

Description

Trend Micro Internet Security Pro 2010 - ActiveX 'extSetOwner()' Remote Code Execution (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by Abysssec · htmlremotewindows
https://www.exploit-db.com/exploits/14878

This exploit targets a remote code execution vulnerability in Trend Micro Internet Security Pro 2010 via an ActiveX control (UfPBCtrl.DLL). It uses a heap spray technique to achieve reliable exploitation, leveraging a specific memory address in mshtml.dll to execute shellcode.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Trend Micro Internet Security Pro 2010 (UfPBCtrl.DLL 17.50.0.1366)
No auth needed
Prerequisites: Victim must visit a malicious webpage hosting the exploit · ActiveX control must be enabled in the browser
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026