Microsoft Windows 11 Version 24H2 Cross Device Service – Elevation of Privilege
#!/usr/bin/env python3
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/env python3
#!/usr/bin/env python3
# Exploit Title: ABB Cylon Aspect Studio 3.08.03 - Binary Planting
# Exploit Title: Microsoft Windows Server 2016 - Win32k Elevation of
# Exploit Title: Zyxel USG FLEX H series uOS 1.31 - Privilege Escalation
#define _WINSOCK_DEPRECATED_NO_WARNINGS
# Exploit Title: RDPGuard 9.9.9 - Privilege Escalation
# Exploit Title: VirtualBox 7.0.16 - Privilege Escalation
# Exploit Title: Microsoft Windows 11 Pro 23H2 - Ancillary Function Driver for WinSock Privilege Escalation
# Exploit title: Microsoft - NTLM Hash Disclosure Spoofing (library-ms)
# Exploit Title: ZTE ZXV10 H201L - RCE via authentication bypass
# Daikin Security Gateway 214 - Remote Password Reset
# Exploit Author: John Page (aka hyp3rlinx)
# Exploit Title: unzip-stream 0.3.1 - Arbitrary File Write
# Exploit Title: Microsoft Windows 11 - Kernel Privilege Escalation
# Exploit Title: Microsoft Windows 11 23h2 - CLFS.sys Elevation of Privilege
# Exploit Title: tar-fs 3.0.0 - Arbitrary File Write/Overwrite
# Exploit Title: AnyDesk 9.0.1 - Unquoted Service Path
# Exploit Title: ASUS ASMB8 iKVM 1.14.51 - Remote Code Execution (RCE)
# Exploit Title: CommScope Ruckus IoT Controller 1.7.1.0 - Undocumented Account
# Exploit Title: qBittorrent 5.0.1 MITM RCE
# Exploit Title: ollama 0.6.4 - SSRF
# Exploit Title: Solstice Pod API Session Key Extraction via API Endpoint
# Exploit Title: Container Breakout with NVIDIA Container Toolkit
# Exploit Title: VeeVPN 1.6.1 - 'VeePNService' Unquoted Service Path
#Exploit Title: Genexus Protection Server 9.7.2.10 - 'protsrvservice' Unquoted Service Path Service Path
# Exploit Title: SolarWinds Kiwi Syslog Server 9.6.7.1 - Unquoted Service Path
# Exploit Title: Oracle Database 12c Release 1 - Unquoted Service Path
# Exploit Title: Bonjour Service - 'mDNSResponder.exe' Unquoted Service
# Exploit Title: Plantronics Hub 3.25.1 – Arbitrary File Read
# Exploit Title: PrusaSlicer 2.6.1 - Arbitrary code execution on g-code export
# Exploit Title: Terratec dmx_6fire USB - Unquoted Service Path
# Exploit Title: AnyDesk 7.0.15 - Unquoted Service Path
# Exploit Title: ESET NOD32 Antivirus 17.0.16.0 - Unquoted Service Path
[+] Credits: John Page (aka hyp3rlinx)
#############################################
# Exploit Title: Rapid7 nexpose - 'nexposeconsole' Unquoted Service Path
# Exploit Title: ASUS Control Center Express 01.06.15 - Unquoted Service Path
# Exploit Title: [title] Dell Security Management Server versions prior to
# Exploit Title: vm2 Sandbox Escape vulnerability
# Exploit Title: LaborOfficeFree 19.10 MySQL Root Password Calculator - CVE-2024-1346
# Exploit Title: KiTTY 0.76.1.13 - Command Injection
# Exploit Title: KiTTY 0.76.1.13 - 'Start Duplicated Session Username' Buffer Overflow
# Exploit Title: KiTTY 0.76.1.13 - 'Start Duplicated Session Hostname' Buffer Overflow
[+] Credits: John Page (aka hyp3rlinx)
#!/usr/bin/python
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Linux-x64 - create a shell with execve() sending argument using XOR (/bin//sh) [55 bytes]
// Exploit Title: Saflok KDF
[+] Credits: John Page (aka hyp3rlinx)