local
local 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
Microsoft Windows – RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=870
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) – NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=865
Macro Expert 4.0 – Multiple Privilege Escalations
# Exploit Title: Macro Expert 4.0 Multiple Elevation of Privilege
Iperius Remote 1.7.0 – Unquoted Service Path Privilege Escalation
# Exploit Title: Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege
MSI – ‘NTIOLib.sys’ / ‘WinIO.sys’ Local Privilege Escalation
#Exploit Title: MSI NTIOLib.sys, WinIO.sys local privilege escalation
Elantech-Smart Pad 11.9.0.0 – Unquoted Service Path Privilege Escalation
# Exploit Title: Elantech Smart-Pad Unquoted Service Path Privilege Escalation
NetDrive 2.6.12 – Unquoted Service Path Privilege Escalation
# Exploit Title: NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege
Zortam Mp3 Media Studio 21.15 – Insecure File Permissions Privilege Escalation
# Exploit Title: Zortam Mp3 Media Studio 21.15 Insecure File Permissions Privilege Escalation
Wise Care 365 4.27 / Wise Disk Cleaner 9.29 – Unquoted Service Path Privilege Escalation
# Exploit Title: Wisecleaner Software Multiple Unquoted Service Path Elevation of Privilege
AnyDesk 2.5.0 – Unquoted Service Path Privilege Escalation
# Exploit Title: AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
Microsoft Windows Kerberos – Security Feature Bypass (MS16-101)
# Exploit Title: Kerberos Security Feature Bypass Vulnerability (Kerberos to NTLM Fallback)
EKG Gadu 1.9~pre+r2855-3+b1 – Local Buffer Overflow
# Exploit developed using Exploit Pack v6.01
Multiple Icecream Apps – Insecure File Permissions Privilege Escalation
# Exploit Title: Multiple Icecream Apps Local Privilege Escalation
WinSMS 3.43 – Insecure File Permissions Privilege Escalation
# Exploit Title: WinSMS 3.43 Local Privilege Escalation
Zapya Desktop 1.803 – ‘ZapyaService.exe’ Local Privilege Escalation
# Exploit Title: Zapya Desktop Version ('ZapyaService.exe') Privilege Escalation
Battle.Net 1.5.0.7963 – Insecure File Permissions Privilege Escalation
# Exploit Title: Battle.Net 1.5.0.7963 Local Privilege Escalation
Sony Playstation 4 (PS4) 3.15 < 3.55 - WebKit Code Execution (PoC)
PS4 3.55 Unsigned Code Execution
WIN-911 7.17.00 – Multiple Vulnerabilities
Title: WIN-911 - Insecure File Permissions EoP
ArcServe UDP 6.0.3792 Update 2 Build 516 – Unquoted Service Path Privilege Escalation
Title: ArcServe UDP - Unquoted Service Path Privilege Escalation
ZKTeco ZKAccess Professional 3.5.3 – Insecure File Permissions Privilege Escalation
ZKTeco ZKAccess Professional 3.5.3 Insecure File Permissions
ZKTeco ZKTime.Net 3.0.1.6 – Insecure File Permissions Privilege Escalation
ZKTeco ZKTime.Net 3.0.1.6 Insecure File Permissions
Cisco ASA / PIX – ‘EPICBANANA’ Local Privilege Escalation
# Exploit Title: Cisco ASA / PIX - Privilege Escalation (EPICBANANA)
Watchguard Firewalls – ‘ESCALATEPLOWMAN’ ifconfig Privilege Escalation
# Exploit Title: WatchGuard Firewalls - ifconfig Privilege Escalation (ESCALATEPLOWMAN)
EyeLock Myris 3.3.2 – SDK Service Unquoted Service Path Privilege Escalation
EyeLock Myris 3.3.2 SDK Service Unquoted Service Path Privilege Escalation
Microsoft Word 2007/2010/2013/2016 – Out-of-Bounds Read Code Execution (MS16-099)
#####################################################################################
Microsoft Windows 7 (x86/x64) – Group Policy Privilege Escalation (MS16-072)
# Exploit Title: Group Policy Elevation of Privilege Vulnerability
VMware Host Guest Client Redirector – DLL Side Loading (Metasploit)
require 'msf/core'
zFTP Client 20061220 – ‘Connection Name’ Local Buffer Overflow
# Exploit developed using Exploit Pack v5.4
mySCADAPro 7 – Local Privilege Escalation
mySCADAProv7 Local Privilege Escalation
VUPlayer 2.49 – ‘.pls’ File Stack Buffer Overflow (DEP Bypass)
#!/usr/bin/python
CoolPlayer+ Portable 2.19.6 – ‘.m3u’ File Stack Overflow (Egghunter + ASLR Bypass)
# Exploit Title: [CoolPlayer+ Portable build 2.19.6 - .m3u Stack Overflow [Egghunter+ASLR bypass]]
Mediacoder 0.8.43.5852 – ‘.m3u’ (SEH)
# Exploit Title: [MediaCoder 0.8.43.5852 - .m3u SEH Exploit]
Rapid7 AppSpider 6.12 – Local Privilege Escalation
Rapid7 AppSpider 6.12 Web Application Vulnerability Scanner Elevation Of Privilege