Microsoft Windows – NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
Windows: NtImpersonateAnonymousToken AC to Non-AC EoP
dos 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Windows: NtImpersonateAnonymousToken AC to Non-AC EoP
Windows: NTFS Owner/Mandatory Label Privilege Bypass EoP
This bug is similar to Jann Horn's issue (https://bugs.chromium.org/p/project-zero/issues/detail?id=851) -- credit sh...
The method "Lowerer::LowerSetConcatStrMultiItem" is used to generate machine code to concatenate strings.
== INTRODUCTION ==
We have discovered that the nt!NtQuerySystemInformation system call invoked with the 138 information class discloses ...
We have discovered that the nt!NtQueryInformationProcess system call invoked with the 76 information class discloses ...
Escape analysis: https://en.wikipedia.org/wiki/Escape_analysis
Here's a snippet of AsmJSByteCodeGenerator::EmitAsmJsFunctionBody.
The optimizations for memory operations may leave empty loops as follows:
1. Call patterns like "Math.max.apply(Math, [1, 2, 3, 4, 5])" and "Math.max.apply(Math, arr)" can be optimized to dir...
The MemoryIntArray class allows processes to share an in-memory array of integers backed by an "ashmem" file descript...
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: DiskBoss Enterprise Server 8.5.12 - Denial of Service
# Exploit Title: Sync Breeze Enterprise Server v10.1.16 - Denial of Service
# Exploit Title: Disk Pulse Enterprise Server v10.1.18 - DOS,
# Exploit Title: VX Search Enterprise Server v10.1.12 - Denial of Service
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1389&desc=6
# Exploit Title: Buffer overflow vulnerability in GetGo Download Manager proxy options 5.3.0.2712
#!/usr/bin/python
# Exploit Title: Buffer overflow in ALLPlayer ALLMediaServer 0.95 and earlier
# Exploit Title: SysGauge Server 3.6.18 - DOS
#!/usr/bin/env python
# Exploit Title: Buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1456
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1358
[CONVISO-17-002] - Zoom Linux Client Stack-based Buffer Overflow Vulnerability
[CONVISO-17-003] - Zoom Linux Client Command Injection Vulnerability (RCE)
#!/usr/bin/python
=============================================
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1373
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1375
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1377
posix_spawn is a complex syscall which takes a lot of arguments from userspace. The third argument
#define _GNU_SOURCE
#define _GNU_SOURCE
Source: http://bugzilla.maptools.org/show_bug.cgi?id=2750
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1372
I have previously detailed the lifetime management paradigms in MIG in the writeups for:
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1405
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1392&desc=2