Oracle VM VirtualBox – Cooperating VMs can Escape from Shared Folder
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1037
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1037
Exploit Title - USBPcap Null Pointer Dereference Privilege Escalation
# Exploit CyberGhost 6.0.4.2205 Privilege Escalation
# Exploit Title: Cisco AnyConnect Start Before Logon (SBL) local privilege escalation. CVE-2017-3813
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1072
# Exploit ShadeYouVPN.com Client v2.0.1.11 for Windows Privilege Escalation
Cimetrics BACnet Explorer 4.0 XXE Vulnerability
Cimetrics BACstac Routing Service 6.2f Local Privilege Escalation
# Exploit IVPN Client for Windows 2.6.6120.33863 Privilege Escalation
#!/bin/bash
[+]#################################################################################################
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=981
# Exploit Title: Viscosity for Windows 1.6.7 Privilege Escalation
== [ Overview ] ===
Exploit Title - Palo Alto Networks Terminal Services Agent Integer Overflow
#!/bin/bash
source: http://www.openwall.com/lists/oss-security/2017/01/24/4
Commit f86a374 ("screen.c: adding permissions check for the logfile name",
# Exploit Title: Microsoft Power Point Java Payload Code Execution
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=967
# Exploit developed using Exploit Pack v7.01
# Exploit Title: aSc Timetables 2017 input field buffer overflow and code execution
# firejail advisory for TOCTOU in --get and --put (local root)
For those who only care about one thing: [the PoC is here.](https://rol.im/kpwned.zip)
Source: https://ricklarabee.blogspot.com/2017/01/virtual-memory-page-tables-and-one-bit.html
Exploit Title : Advanced Desktop Locker [ Locker Bypass ]
#define _POSIX_C_SOURCE 200212
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=989
// Source: https://github.com/sensepost/ms16-098/tree/b85b8dfdd20a50fc7bc6c40337b8de99d6c4db80
# Exploit Title: Shutter user-assisted remote code execution
=====================================================
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1010
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=959
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=941
#!/usr/bin/env python
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=965
#!/bin/bash
Both of these issues were reported to the Apport maintainers and a fix was released on 2016-12-14. The CrashDB code i...
Source: https://scarybeastsecurity.blogspot.com/2016/12/redux-compromising-linux-using-snes.html