EIP-2026-119642
PRE-CVEMicrosoft Windows Defender - VBScript Detection Bypass
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119642. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a bypass for Windows Defender's detection of TrojanWin32Powessere.G by leveraging rundll32.exe with a crafted VBScript command. The technique involves inserting arbitrary text into the mshtml parameter path to evade detection while executing arbitrary commands (e.g., calc.exe).
Description
Microsoft Windows Defender - VBScript Detection Bypass
Exploits (1)
This exploit demonstrates a bypass for Windows Defender's detection of TrojanWin32Powessere.G by leveraging rundll32.exe with a crafted VBScript command. The technique involves inserting arbitrary text into the mshtml parameter path to evade detection while executing arbitrary commands (e.g., calc.exe).