EIP-2026-119667
PRE-CVEMicrosoft Windows mshta.exe 2019 - XML External Entity Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119667. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft Windows mshta.exe, allowing local data theft and reconnaissance by crafting a malicious HTA file. The PoC includes a multi-program recon technique and checks for virtual machine environments.
Description
Microsoft Windows mshta.exe 2019 - XML External Entity Injection
Exploits (1)
This exploit demonstrates an XML External Entity (XXE) injection vulnerability in Microsoft Windows mshta.exe, allowing local data theft and reconnaissance by crafting a malicious HTA file. The PoC includes a multi-program recon technique and checks for virtual machine environments.