windows
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
SysGauge 1.5.18 – Remote Buffer Overflow
# Exploit Title: SysGauge 1.5.18 – buffer overflow in SMTP connection verification function leads to code execution
Cisco AnyConnect Secure Mobility Client 4.3.04027 – Local Privilege Escalation
# Exploit Title: Cisco AnyConnect Start Before Logon (SBL) local privilege escalation. CVE-2017-3813
Synchronet BBS 3.16c – Denial of Service
# Exploit Title: Synchronet BBS 3.16c for Windows – Multiple vulnerabilities
BlueIris 4.5.1.4 – Denial of Service
import socket
Disk Savvy Enterprise 9.4.18 – Remote Buffer Overflow (SEH)
# Exploit Title: DiskSavvy Enterprise 9.4.18 - Remote buffer overflow - SEH overwrite with WoW64 egghunters
EasyCom For PHP 4.0.0 – Denial of Service
[+] Credits: John Page AKA Hyp3rlinX
EasyCom For PHP 4.0.0 – Buffer Overflow (PoC)
[+] Credits: John Page AKA Hyp3rlinX
Microsoft Office PowerPoint 2010 – GDI ‘GDI32!ConvertDxArray’ Insufficient Bounds Check
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=951
Microsoft Office PowerPoint 2010 – MSO/OART Heap Out-of-Bounds Access
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=950
Microsoft Office PowerPoint 2010 – ‘MSO!Ordinal5429’ Missing Length Check Heap Corruption
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=949
Sawmill Enterprise 8.7.9 – Authentication Bypass
[+] Credits: John Page AKA Hyp3rlinx
GOM Player 2.3.10.5266 – ‘.fpx’ Denial of Service
# Exploit Title: GOM Player 2.3.10.5266 - Remote heap corruption (.fpx)
NVIDIA Driver 375.70 – Buffer Overflow in Command Buffer Submission
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1012
NVIDIA Driver 375.70 – DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=985
Microsoft Windows – ‘gdi32.dll’ EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=992
ShadeYouVPN Client 2.0.1.11 – Local Privilege Escalation
# Exploit ShadeYouVPN.com Client v2.0.1.11 for Windows Privilege Escalation
Cimetrics BACnet Explorer 4.0 – XML External Entity Injection
Cimetrics BACnet Explorer 4.0 XXE Vulnerability
Cimetrics BACstac 6.2f – Local Privilege Escalation
Cimetrics BACstac Routing Service 6.2f Local Privilege Escalation
SonicDICOM PACS 2.3.2 – Privilege Escalation
SonicDICOM PACS 2.3.2 Remote Vertical Privilege Escalation Exploit
SonicDICOM PACS 2.3.2 – Cross-Site Request Forgery (Add Admin)
SonicDICOM PACS 2.3.2 CSRF Add Admin Exploit
SonicDICOM PACS 2.3.2 – Cross-Site Scripting
SonicDICOM PACS 2.3.2 Multiple Stored Cross-Site Scripting Vulnerabilities
IVPN Client 2.6.1 – Local Privilege Escalation
# Exploit IVPN Client for Windows 2.6.6120.33863 Privilege Escalation
Ghostscript 9.20 – ‘Filename’ Command Execution
[+]#################################################################################################
Microsoft Windows 10 – SMBv3 Tree Connect (PoC)
# Full Proof of Concept:
Viscosity 1.6.7 – Local Privilege Escalation
# Exploit Title: Viscosity for Windows 1.6.7 Privilege Escalation
Palo Alto Networks Terminal Services Agent 7.0.3-13 – Integer Overflow
Exploit Title - Palo Alto Networks Terminal Services Agent Integer Overflow
Geutebrueck GCore 1.3.8.42/1.4.2.37 – Remote Code Execution (Metasploit)
# Exploit Title: Geutebrueck GCore X64 Full RCE Bufferoverflow for Metasploit
Cisco WebEx – ‘nativeMessaging’ Remote Command Execution
Cisco WebEx Exploit
Microsoft Power Point 2016 – Java Code Execution
# Exploit Title: Microsoft Power Point Java Payload Code Execution
WinaXe Plus 8.7 – Remote Buffer Overflow
# Exploit Title: WinaXe Plus 8.7 - lpr remote buffer overflow
Mozilla Firefox < 50.1.0 - Use-After-Free
Firefox < 50.1.0 Use After Free (CVE-2016-9899)
aSc Timetables 2017 – Local Buffer Overflow
# Exploit Title: aSc Timetables 2017 input field buffer overflow and code execution
Boxoft Wav 1.0 – Buffer Overflow
Document Title:
DiskBoss Enterprise 7.5.12 – ‘POST’ Remote Buffer Overflow (SEH)
#!/usr/bin/python
Microsoft Windows Kernel – ‘win32k.sys NtSetWindowLongPtr’ Local Privilege Escalation (MS16-135) (2)
Source: https://ricklarabee.blogspot.com/2017/01/virtual-memory-page-tables-and-one-bit.html
Advanced Desktop Locker 6.0.0 – Lock Screen Bypass
Exploit Title : Advanced Desktop Locker [ Locker Bypass ]
Microsoft Edge (Windows 10) – ‘chakra.dll’ Information Leak / Type Confusion Remote Code Execution
Source: https://github.com/theori-io/chakra-2016-11
Kaspersky 17.0.0 – Local CA Root Incorrectly Protected
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=989
Internet Download Accelerator 6.10.1.1527 – FTP Buffer Overflow (SEH)
#!/usr/bin/python
SapLPD 7.40 – Denial of Service
# Exploit Title: SAPlpd 7.40 Denial of Service
Wampserver 3.0.6 – Insecure File Permissions Privilege Escalation
=====================================================
FTPShell Server 6.36 – ‘.csv’ Local Denial of Service
#Exploit FTPShell server 6.36 '.csv' Crash(PoC)