Microsoft Windows Subsystem for Linux – ‘execve()’ Local Privilege Escalation
#define _GNU_SOURCE
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#define _GNU_SOURCE
## Vulnerability Summary
Exploit Title - System Shield AntiVirus & AntiSpyware Arbitrary Write Privilege Escalation
Product: systemd (systemd-tmpfiles)
#!/bin/bash
#!/usr/bin/env ruby
EDB Note ~ http://ps3xploit.com/help/dumper.html
# SSD Advisory – Oracle VirtualBox Multiple Guest to Host Escape Vulnerabilities
All blizzard games are installed alongside a shared tool called "Blizzard Update Agent", investor.activision.com clai...
#Tested on HP Connected Backup version 8.8.2.0 on Windows 7 x64
#define _GNU_SOURCE
// ConsoleApplication1.cpp : Defines the entry point for the console application.
Windows: Local XPS Print Spooler Sandbox Escape
# PS4 4.05 Kernel Exploit
RCE Security Advisory
Qualys Security Advisory
Recently I was working on an security issue in some other software that has yet to be disclosed which created a rathe...
# With CVE-2017-7643 I disclosed a command injection vulnerablity in the KLoader
# A couple of weeks ago I disclosed a local root privesc in Hashicorp's
# I have previously disclosed a couple of bugs in Hashicorp's vagrant-vmware-fusion plugin for vagrant.
# After three CVEs and multiple exploits disclosed to Hashicorp they have finally upped their game with this plugin. ...
# Sera is a free app for mac and iOS that lets you unlock your mac automatically
# I recently blogged about how the installation process of version 5.0.0 of this
# Another day, another root privesc bug in this plugin. Not quite so serious this
# Arq Backup from Haystack Software is a great application for backing up macs and
# I recently blogged about the prevalence of escalation hijack vulnerabilities amongst macOS applications. One exampl...
# TeamViewer Permissions Hook V1
While using NET::Ftp I realised you could get command execution through "malicious" file names.
## Source: https://twitter.com/lemiorhan/status/935578694541770752 & https://forums.developer.apple.com/thread/79235
[+] Exploit Title: Diving Log 6.0 XXE Injection
#!/usr/bin/python
## Vulnerability Summary
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1332
#!/usr/bin/env python
Exploit Title - IKARUS anti.virus Arbitrary Write Privilege Escalation
[+] Credits: John Page a.k.a hyp3rlinx
// Proof of concept exploit for waitid bug introduced in Linux Kernel 4.13
Exploit Title - Vir.IT eXplorer Anti-Virus Arbitrary Write Privilege Escalation