<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>binary — PoC Archive</title><link>https://poc.intelseclab.com/pocs/binary/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/binary/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-21508. Status: Patched. Affects: Microsoft Windows Media Player / WUDFHost.exe. Tags: windows, dll-hijack, lpe, privilege-escalation, media-player, wudfhost, session0, com-hijack, CVE-2026-21508.</description><category>binary</category><category>High</category><category>windows</category><category>dll-hijack</category><category>lpe</category><category>privilege-escalation</category><category>media-player</category><category>wudfhost</category><category>session0</category><category>com-hijack</category><category>CVE-2026-21508</category></item><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-23111. Status: Patched. Affects: Linux kernel (nf_tables subsystem). Tags: linux, kernel, nftables, nf-tables, uaf, catchall, lpe, privilege-escalation, slab-spray, kaslr-bypass, rop, namespace, CVE-2026-23111.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>nftables</category><category>nf-tables</category><category>uaf</category><category>catchall</category><category>lpe</category><category>privilege-escalation</category><category>slab-spray</category><category>kaslr-bypass</category><category>rop</category><category>namespace</category><category>CVE-2026-23111</category></item><item><title>Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-53361. Status: Patched. Affects: Linux Kernel (AF_UNIX socket garbage collector). Tags: linux, kernel, af-unix, garbage-collector, msg-peek, uaf, container-escape, lpe, slub, dirty-pagetable, CVE-2026-53361.</description><category>binary</category><category>Critical</category><category>linux</category><category>kernel</category><category>af-unix</category><category>garbage-collector</category><category>msg-peek</category><category>uaf</category><category>container-escape</category><category>lpe</category><category>slub</category><category>dirty-pagetable</category><category>CVE-2026-53361</category></item><item><title>Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-2764-firefox-jit-uaf/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-2764-firefox-jit-uaf/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-2764 / MFSA 2026-13. Status: Patched. Affects: Mozilla Firefox (SpiderMonkey JavaScript Engine). Tags: firefox, spidermonkey, jit, uaf, type-confusion, wasm, browser, ionmonkey, baseline, proxy, CVE-2026-2764.</description><category>binary</category><category>High</category><category>firefox</category><category>spidermonkey</category><category>jit</category><category>uaf</category><category>type-confusion</category><category>wasm</category><category>browser</category><category>ionmonkey</category><category>baseline</category><category>proxy</category><category>CVE-2026-2764</category></item><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64531. Status: Patched. Affects: Linux kernel, Open vSwitch (OVS) kernel module, conntrack subsystem. Tags: linux, kernel, lpe, openvswitch, ovs, conntrack, netlink, memory-corruption, sudoers, CVE-2026-64531.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>openvswitch</category><category>ovs</category><category>conntrack</category><category>netlink</category><category>memory-corruption</category><category>sudoers</category><category>CVE-2026-64531</category></item><item><title>Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-17106-copyescape-docker-cp-host-takeover/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-17106. Status: Patched. Affects: Docker Engine / Docker Desktop, docker cp CLI command. Tags: docker, container-escape, race-condition, symlink, path-traversal, runc, host-takeover, linux, macos, CWE-367, CWE-59, CVE-2026-17106.</description><category>binary</category><category>Critical</category><category>docker</category><category>container-escape</category><category>race-condition</category><category>symlink</category><category>path-traversal</category><category>runc</category><category>host-takeover</category><category>linux</category><category>macos</category><category>CWE-367</category><category>CWE-59</category><category>CVE-2026-17106</category></item><item><title>Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</guid><description>High severity (CVSS 7.8) — binary · Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11. Status: Unpatched. Affects: Microsoft Windows Defender (Antimalware Service Executable / MsMpEng.exe), threat remediation subsystem. Tags: windows, windows-defender, lpe, privilege-escalation, 0day, patch-bypass, cloud-files, cfapi, object-manager, symlink, wer, dll-sideload, CWE-59, CWE-426, microsoft, rogueplanet, shieldbreak.</description><category>binary</category><category>High</category><category>windows</category><category>windows-defender</category><category>lpe</category><category>privilege-escalation</category><category>0day</category><category>patch-bypass</category><category>cloud-files</category><category>cfapi</category><category>object-manager</category><category>symlink</category><category>wer</category><category>dll-sideload</category><category>CWE-59</category><category>CWE-426</category><category>microsoft</category><category>rogueplanet</category><category>shieldbreak</category></item><item><title>Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_cve-2026-64561-zapscape-kvm-shadow-mmu-guest-to-host/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-64561. Status: Patched. Affects: Linux kernel, KVM/x86 shadow-MMU (nested EPT/NPT shadowing) — arch/x86/kvm/mmu/mmu.c and arch/x86/kvm/mmu/paging_tmpl.h. Tags: linux-kernel, kvm, x86, shadow-mmu, nested-virtualization, svm, npt, ept, guest-to-host-escape, vm-escape, use-after-free, CWE-416, cross-cache, kaslr-bypass, usermode-helper, virtualization.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>kvm</category><category>x86</category><category>shadow-mmu</category><category>nested-virtualization</category><category>svm</category><category>npt</category><category>ept</category><category>guest-to-host-escape</category><category>vm-escape</category><category>use-after-free</category><category>CWE-416</category><category>cross-cache</category><category>kaslr-bypass</category><category>usermode-helper</category><category>virtualization</category></item><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</guid><description>High severity — binary · NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier). Status: Unpatched — Barrier is unmaintained with no vendor fix; patched successor Deskflow covers the same issue via CVE-2026-41477 / GHSA-6rx5-g478-775c. Affects: Barrier (debauchee), Windows service daemon barrierd.exe. Tags: barrier, barrierd, windows, ipc, tcp-24801, unauthenticated, lpe, privilege-escalation, system, cwe-306, local.</description><category>binary</category><category>High</category><category>barrier</category><category>barrierd</category><category>windows</category><category>ipc</category><category>tcp-24801</category><category>unauthenticated</category><category>lpe</category><category>privilege-escalation</category><category>system</category><category>cwe-306</category><category>local</category></item><item><title>Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-49176. Status: Weaponized — SYSTEM shell confirmed against a real, vulnerable Windows 11 build. Affects: Windows WalletService (Windows.ApplicationModel.Wallet WinRT API, backed by an ESE/Jet Blue database under the caller's Documents\Wallet folder). Tags: windows, walletservice, lpe, privilege-escalation, ese, extensible-storage-engine, known-folder-redirection, persisted-callback, local.</description><category>binary</category><category>High</category><category>windows</category><category>walletservice</category><category>lpe</category><category>privilege-escalation</category><category>ese</category><category>extensible-storage-engine</category><category>known-folder-redirection</category><category>persisted-callback</category><category>local</category></item><item><title>ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-46316-itscape-kvm-arm64-vgic-its-escape/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2026-46316 (GHSA-qcxh-2cm7-9fcc). Status: Weaponized. Affects: Linux kernel, KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation (arch/arm64/kvm/vgic/vgic-its.c). Tags: linux-kernel, kvm, arm64, vgic-its, guest-to-host-escape, vm-escape, double-free, use-after-free, kaslr-bypass, heap-grooming, virtualization.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>kvm</category><category>arm64</category><category>vgic-its</category><category>guest-to-host-escape</category><category>vm-escape</category><category>double-free</category><category>use-after-free</category><category>kaslr-bypass</category><category>heap-grooming</category><category>virtualization</category></item><item><title>GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</guid><description>High severity — binary · N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27). Status: Unpatched. Affects: Windows Recovery Environment (WinRE) — Microsoft Defender Offline Scan launch path (ReAgent.xml scheduled operation). Tags: windows, bitlocker, winre, defender, offline-scan, trust-boundary-bypass, zero-day, unpatched, physical-access, local.</description><category>binary</category><category>High</category><category>windows</category><category>bitlocker</category><category>winre</category><category>defender</category><category>offline-scan</category><category>trust-boundary-bypass</category><category>zero-day</category><category>unpatched</category><category>physical-access</category><category>local</category></item><item><title>V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-19_cve-2026-14431-v8-array-iterator-maglev-type-confusion/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-19_cve-2026-14431-v8-array-iterator-maglev-type-confusion/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-14431. Status: PoC — real, working sandboxed read/write primitives (addrof/fakeobj); no sandbox-escape/RCE chain published (author states this is still in progress). Affects: V8 JavaScript engine (Google Chrome and other Chromium-based browsers). Tags: v8, javascript-engine, chromium, maglev, type-confusion, array-iterator, cwe-843, sandboxed-read-write, memory-corruption.</description><category>binary</category><category>High</category><category>v8</category><category>javascript-engine</category><category>chromium</category><category>maglev</category><category>type-confusion</category><category>array-iterator</category><category>cwe-843</category><category>sandboxed-read-write</category><category>memory-corruption</category></item><item><title>LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-19_legacyhive-user-profile-service-hive-load-lpe/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-19_legacyhive-user-profile-service-hive-load-lpe/</guid><description>High severity — binary. Status: Weaponized. Affects: Microsoft Windows user profile service / registry hive loading path. Tags: windows, lpe, user-profile-service, registry-hive, usrclass.dat, oplock, symbolic-link.</description><category>binary</category><category>High</category><category>windows</category><category>lpe</category><category>user-profile-service</category><category>registry-hive</category><category>usrclass.dat</category><category>oplock</category><category>symbolic-link</category></item><item><title>Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499 (aka "GhostLock"). Status: Weaponized (per Nebula Security disclosure); no exploit code mirrored into this repo, see Notes. Affects: Linux kernel — rtmutex priority-inheritance (futex-PI) subsystem, CONFIG_FUTEX_PI. Tags: linux-kernel, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, container-escape, kernelctf, ghostlock.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>container-escape</category><category>kernelctf</category><category>ghostlock</category></item><item><title>Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-32463-sudo-chroot-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-32463-sudo-chroot-privesc/</guid><description>Critical severity (CVSS 9.3) — binary · CVE-2025-32463. Status: Weaponized. Affects: sudo (-R / --chroot option). Tags: sudo, chroot, privilege-escalation, nsswitch, nss-module, local-privesc, linux, shell, c.</description><category>binary</category><category>Critical</category><category>sudo</category><category>chroot</category><category>privilege-escalation</category><category>nsswitch</category><category>nss-module</category><category>local-privesc</category><category>linux</category><category>shell</category><category>c</category></item><item><title>RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-49844-redis-lua-uaf-jop-rce/</guid><description>Critical severity (CVSS 9.9) — binary · CVE-2025-49844. Status: Weaponized. Affects: Redis (embedded Lua scripting engine). Tags: redis, lua, use-after-free, uaf, memory-corruption, jop, jump-oriented-programming, shellcode, iced-x86, docker, cwe-416, rce.</description><category>binary</category><category>Critical</category><category>redis</category><category>lua</category><category>use-after-free</category><category>uaf</category><category>memory-corruption</category><category>jop</category><category>jump-oriented-programming</category><category>shellcode</category><category>iced-x86</category><category>docker</category><category>cwe-416</category><category>rce</category></item><item><title>Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-54957-dolby-decoder-oob-write/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-54957-dolby-decoder-oob-write/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2025-54957. Status: Weaponized. Affects: Dolby Digital Plus (DDPlus) Unified Decoder — bundled in Android media stack, iOS/macOS CoreAudio-adjacent decoders, and ChromeOS. Tags: dolby, ddplus, ac-3, ec-3, audio-codec, out-of-bounds-write, integer-overflow, zero-click, android, ios, macos, heap-corruption.</description><category>binary</category><category>Critical</category><category>dolby</category><category>ddplus</category><category>ac-3</category><category>ec-3</category><category>audio-codec</category><category>out-of-bounds-write</category><category>integer-overflow</category><category>zero-click</category><category>android</category><category>ios</category><category>macos</category><category>heap-corruption</category></item><item><title>XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20698-xnu-pf-route-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20698-xnu-pf-route-heap-overflow/</guid><description>High severity — binary · CVE-2026-20698. Status: PoC. Affects: XNU kernel routing socket subsystem (PF_ROUTE, bsd/net/rtsock.c / bsd/net/radix.c). Tags: xnu, kernel, ios, macos, pf_route, routing-socket, heap-overflow, radix-tree, kernel-panic, bounds-safety.</description><category>binary</category><category>High</category><category>xnu</category><category>kernel</category><category>ios</category><category>macos</category><category>pf_route</category><category>routing-socket</category><category>heap-overflow</category><category>radix-tree</category><category>kernel-panic</category><category>bounds-safety</category></item><item><title>XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3609-xigncode3-lsass-credential-dump/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3609-xigncode3-lsass-credential-dump/</guid><description>High severity — binary · CVE-2026-3609. Status: Weaponized. Affects: Wellbia XIGNCODE3 anti-cheat driver (xhunter1.sys). Tags: lsass, credential-dumping, anti-cheat, kernel-driver, ppl-bypass, xigncode3, windows, byovd.</description><category>binary</category><category>High</category><category>lsass</category><category>credential-dumping</category><category>anti-cheat</category><category>kernel-driver</category><category>ppl-bypass</category><category>xigncode3</category><category>windows</category><category>byovd</category></item><item><title>Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32202-lnk-idcontrolw-builder/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32202-lnk-idcontrolw-builder/</guid><description>High severity — binary · CVE-2026-32202 (related: CVE-2026-21510). Status: PoC. Affects: Windows Shell (shell32.dll) / Windows Explorer. Tags: lnk, shell32, windows, apt28, smb-coercion, zero-click, reverse-engineering, control-panel.</description><category>binary</category><category>High</category><category>lnk</category><category>shell32</category><category>windows</category><category>apt28</category><category>smb-coercion</category><category>zero-click</category><category>reverse-engineering</category><category>control-panel</category></item><item><title>Windows Secure Kernel (VTL1/VSM) Memory Corruption PoC (CVE-2026-26179 / ZDI-26-276)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-26179-secure-kernel-vsm-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-26179-secure-kernel-vsm-poc/</guid><description>High severity — binary · CVE-2026-26179 / ZDI-26-276. Status: PoC. Affects: Windows Secure Kernel / Virtual Secure Mode (VSM), Virtual Trust Level 1 (VTL1) transfer functions (nt!VslpLockPagesForTransfer, VslpEnterIumSecureMode, nt!VslpUnlockPagesForTransfer). Tags: secure-kernel, vsm, vtl1, windows-kernel, hyper-v, mdl, memory-corruption, driver.</description><category>binary</category><category>High</category><category>secure-kernel</category><category>vsm</category><category>vtl1</category><category>windows-kernel</category><category>hyper-v</category><category>mdl</category><category>memory-corruption</category><category>driver</category></item><item><title>Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-42978. Status: PoC. Affects: Windows Push Notifications service (WpnService, wpncore.dll). Tags: windows, kernel, wpnservice, use-after-free, race-condition, toctou, privilege-escalation, etw, sysmon, patch-diffing.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>wpnservice</category><category>use-after-free</category><category>race-condition</category><category>toctou</category><category>privilege-escalation</category><category>etw</category><category>sysmon</category><category>patch-diffing</category></item><item><title>Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-29923-pstrip64-driver-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-29923-pstrip64-driver-lpe/</guid><description>Critical severity — binary · CVE-2026-29923. Status: Weaponized. Affects: pstrip64.sys kernel driver (EnTech Taiwan PowerStrip, up to version 3.90.736). Tags: byovd, windows-kernel, lpe, physical-memory, eprocess, token-theft, driver, ioctl.</description><category>binary</category><category>Critical</category><category>byovd</category><category>windows-kernel</category><category>lpe</category><category>physical-memory</category><category>eprocess</category><category>token-theft</category><category>driver</category><category>ioctl</category></item><item><title>Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</guid><description>High severity — binary · CVE-2026-40369. Status: PoC. Affects: Windows kernel (ntoskrnl.exe). Tags: windows, kernel, lpe, privilege-escalation, token-stealing, sedebugprivilege, ntoskrnl, local.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>token-stealing</category><category>sedebugprivilege</category><category>ntoskrnl</category><category>local</category></item><item><title>Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</guid><description>High severity — binary · CVE-2026-49160. Status: PoC. Affects: Windows HTTP.sys kernel-mode driver (Windows 10 build 26100 confirmed in crash logs). Tags: windows, http.sys, kernel, http2, dos, bsod, memory-corruption, integer-overflow.</description><category>binary</category><category>High</category><category>windows</category><category>http.sys</category><category>kernel</category><category>http2</category><category>dos</category><category>bsod</category><category>memory-corruption</category><category>integer-overflow</category></item><item><title>Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20817-windows-wer-alpc-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20817-windows-wer-alpc-lpe/</guid><description>High severity — binary · CVE-2026-20817. Status: PoC. Affects: Windows Error Reporting Service (WerSvc). Tags: windows, wersvc, alpc, lpe, privilege-escalation, ntdll, system32, native-cpp.</description><category>binary</category><category>High</category><category>windows</category><category>wersvc</category><category>alpc</category><category>lpe</category><category>privilege-escalation</category><category>ntdll</category><category>system32</category><category>native-cpp</category></item><item><title>Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2636-clfs-sys-bsod/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2636-clfs-sys-bsod/</guid><description>Medium severity — binary · CVE-2026-2636. Status: PoC. Affects: Windows Common Log File System driver (CLFS.sys, version 10.0.22621.5037 used as reference). Tags: clfs, windows-kernel-driver, bsod, denial-of-service, cwe-159, irp, kebugcheckex, unprivileged.</description><category>binary</category><category>Medium</category><category>clfs</category><category>windows-kernel-driver</category><category>bsod</category><category>denial-of-service</category><category>cwe-159</category><category>irp</category><category>kebugcheckex</category><category>unprivileged</category></item><item><title>VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-35250-virtualbox-vbva-integer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-35250-virtualbox-vbva-integer-overflow/</guid><description>Low severity (CVSS 2.3) — binary · CVE-2026-35250. Status: PoC. Affects: Oracle VirtualBox — DevVGA_VBVA.cpp. Tags: virtualbox, integer-overflow, dos, vbva, guest-to-host, cwe-190, ai-assisted-research.</description><category>binary</category><category>Low</category><category>virtualbox</category><category>integer-overflow</category><category>dos</category><category>vbva</category><category>guest-to-host</category><category>cwe-190</category><category>ai-assisted-research</category></item><item><title>Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-44656-vim-modeline-path-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-44656-vim-modeline-path-command-injection/</guid><description>High severity — binary · CVE-2026-44656. Status: PoC. Affects: Vim. Tags: vim, modeline, command-injection, backtick-expansion, path-option, local-code-execution.</description><category>binary</category><category>High</category><category>vim</category><category>modeline</category><category>command-injection</category><category>backtick-expansion</category><category>path-option</category><category>local-code-execution</category></item><item><title>V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-6307-longinus-v8-exploit-kit/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-6307-longinus-v8-exploit-kit/</guid><description>Critical severity — binary · CVE-2026-6307. Status: Weaponized. Affects: V8 JavaScript engine (Chromium-based browsers). Tags: v8, javascript-engine, browser-exploit, memory-corruption, yara, exploit-kit.</description><category>binary</category><category>Critical</category><category>v8</category><category>javascript-engine</category><category>browser-exploit</category><category>memory-corruption</category><category>yara</category><category>exploit-kit</category></item><item><title>snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</guid><description>High severity — binary · CVE-2026-3888. Status: Weaponized. Affects: snapd (snap-confine writable-mimic / systemd-tmpfiles handling). Tags: snapd, snap-confine, linux, local-privilege-escalation, race-condition, systemd-tmpfiles, mount-namespace.</description><category>binary</category><category>High</category><category>snapd</category><category>snap-confine</category><category>linux</category><category>local-privilege-escalation</category><category>race-condition</category><category>systemd-tmpfiles</category><category>mount-namespace</category></item><item><title>Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21018-samsung-sveservice-oob-write-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21018-samsung-sveservice-oob-write-lpe/</guid><description>High severity — binary · CVE-2026-21018 (Samsung SVE-2026-0478, SMR May 2026). Status: PoC. Affects: Samsung SveService (com.sec.sve) system service and its libsvejni.so native library. Tags: android, samsung, binder, native, out-of-bounds-write, jni, lpe, memcpy, memset.</description><category>binary</category><category>High</category><category>android</category><category>samsung</category><category>binder</category><category>native</category><category>out-of-bounds-write</category><category>jni</category><category>lpe</category><category>memcpy</category><category>memset</category></item><item><title>Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20980-samsung-android-at-command-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20980-samsung-android-at-command-lpe/</guid><description>Critical severity — binary · CVE-2026-20980 (chained with CVE-2026-20981 and CVE-2026-20982). Status: PoC. Affects: Samsung Android AT-command distribution stack (at_distributor / libpacm_client.so, FacAtFunction system app, ShortcutService). Tags: android, samsung, at-command, privilege-escalation, usb, system-server, exploit-chain, java, apk.</description><category>binary</category><category>Critical</category><category>android</category><category>samsung</category><category>at-command</category><category>privilege-escalation</category><category>usb</category><category>system-server</category><category>exploit-chain</category><category>java</category><category>apk</category></item><item><title>rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-27831-rldns-heap-oob-read-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-27831-rldns-heap-oob-read-dos/</guid><description>Medium severity — binary · CVE-2026-27831. Status: PoC. Affects: rldns 1.3 (open-source DNS server). Tags: dns, heap-overflow, out-of-bounds-read, denial-of-service, rldns, memory-corruption, x86_64.</description><category>binary</category><category>Medium</category><category>dns</category><category>heap-overflow</category><category>out-of-bounds-read</category><category>denial-of-service</category><category>rldns</category><category>memory-corruption</category><category>x86_64</category></item><item><title>PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</guid><description>Critical severity — binary · CVE-2026-2005. Status: PoC. Affects: PostgreSQL pgcrypto extension (PGP session-key parsing). Tags: postgresql, pgcrypto, heap-overflow, aslr-bypass, privilege-escalation, pgp, memory-corruption.</description><category>binary</category><category>Critical</category><category>postgresql</category><category>pgcrypto</category><category>heap-overflow</category><category>aslr-bypass</category><category>privilege-escalation</category><category>pgp</category><category>memory-corruption</category></item><item><title>Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3437-portwell-sys-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3437-portwell-sys-lpe/</guid><description>High severity — binary · CVE-2026-3437. Status: PoC. Affects: Portwell Engineering Toolkits driver, portwell.sys (v4.8.2). Tags: byovd, windows-driver, kernel, lpe, physical-memory, ioctl, privilege-escalation.</description><category>binary</category><category>High</category><category>byovd</category><category>windows-driver</category><category>kernel</category><category>lpe</category><category>physical-memory</category><category>ioctl</category><category>privilege-escalation</category></item><item><title>PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</guid><description>High severity — binary · CVE-2026-43494. Status: PoC. Affects: Linux kernel (RDS zerocopy send path + io_uring fixed buffers). Tags: linux-kernel, lpe, double-free, use-after-free, rds, io_uring, page-cache-overwrite, x86_64, nasm, asm, local, root-shell.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>double-free</category><category>use-after-free</category><category>rds</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>nasm</category><category>asm</category><category>local</category><category>root-shell</category></item><item><title>Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-14459-pardus-software-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-14459-pardus-software-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-14459 (also covers CVE-2026-14460). Status: Weaponized. Affects: pardus-software (Pardus Software Center). Tags: linux, pardus, privilege-escalation, polkit, pkexec, apt-injection, argument-injection, local-dos.</description><category>binary</category><category>High</category><category>linux</category><category>pardus</category><category>privilege-escalation</category><category>polkit</category><category>pkexec</category><category>apt-injection</category><category>argument-injection</category><category>local-dos</category></item><item><title>PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</guid><description>High severity — binary · CVE-2026-41651. Status: PoC. Affects: PackageKit daemon (packagekitd). Tags: linux, packagekit, toctou, race-condition, lpe, polkit, privilege-escalation, dbus.</description><category>binary</category><category>High</category><category>linux</category><category>packagekit</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>polkit</category><category>privilege-escalation</category><category>dbus</category></item><item><title>Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21986-virtualbox-shared-folder-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21986-virtualbox-shared-folder-dos/</guid><description>Medium severity (CVSS 7.1) — binary · CVE-2026-21986. Status: PoC. Affects: Oracle VM VirtualBox — Shared Folders kernel driver (VBoxMiniRdr, Windows guest). Tags: virtualbox, denial-of-service, kernel-memory-exhaustion, ioctl, shared-folders, windows-driver, non-paged-pool.</description><category>binary</category><category>Medium</category><category>virtualbox</category><category>denial-of-service</category><category>kernel-memory-exhaustion</category><category>ioctl</category><category>shared-folders</category><category>windows-driver</category><category>non-paged-pool</category></item><item><title>OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-33317-optee-pkcs11-heap-oob-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-33317-optee-pkcs11-heap-oob-write/</guid><description>High severity (CVSS 8.7) — binary · CVE-2026-33317 (GHSA-8cqw-mg7v-c9p9). Status: PoC. Affects: OP-TEE OS — PKCS#11 Trusted Application (optee_os, ta/pkcs11). Tags: optee, trustzone, pkcs11, secure-world, heap-corruption, oob-write, qemu, trusted-application.</description><category>binary</category><category>High</category><category>optee</category><category>trustzone</category><category>pkcs11</category><category>secure-world</category><category>heap-corruption</category><category>oob-write</category><category>qemu</category><category>trusted-application</category></item><item><title>Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</guid><description>Medium severity — binary · CVE-2026-3008. Status: PoC. Affects: Notepad++ 8.9.3. Tags: notepad++, format-string, wsprintfw, dos, information-disclosure, localization, windows.</description><category>binary</category><category>Medium</category><category>notepad++</category><category>format-string</category><category>wsprintfw</category><category>dos</category><category>information-disclosure</category><category>localization</category><category>windows</category></item><item><title>MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1668-mips-switch-kernel-rce/</guid><description>Critical severity — binary · CVE-2026-1668. Status: Weaponized. Affects: MIPS-based managed switch firmware (web management HTTP server), e.g. SG2005P/SG2008/SG2016P/SG2210MP/SG2218/SG2428/SG3210/SL2428/TL-SG2428 series firmware built around 2025-10-31. Tags: mips, embedded-linux, kernel-exploit, firmware, managed-switch, reverse-shell, pre-auth, shellcode.</description><category>binary</category><category>Critical</category><category>mips</category><category>embedded-linux</category><category>kernel-exploit</category><category>firmware</category><category>managed-switch</category><category>reverse-shell</category><category>pre-auth</category><category>shellcode</category></item><item><title>MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36981-minitool-kernel-driver-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36981-minitool-kernel-driver-lpe/</guid><description>High severity — binary · CVE-2026-36981. Status: PoC. Affects: MiniTool pwdrvio.sys kernel driver. Tags: minitool, kernel-driver, write-what-where, lpe, arbitrary-kernel-write, windows.</description><category>binary</category><category>High</category><category>minitool</category><category>kernel-driver</category><category>write-what-where</category><category>lpe</category><category>arbitrary-kernel-write</category><category>windows</category></item><item><title>MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36980-minitool-kernel-driver-bsod-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36980-minitool-kernel-driver-bsod-dos/</guid><description>Medium severity — binary · CVE-2026-36980. Status: PoC. Affects: MiniTool pwdrvio.sys kernel driver. Tags: minitool, kernel-driver, ioctl, bsod, dos, pool-corruption, windows.</description><category>binary</category><category>Medium</category><category>minitool</category><category>kernel-driver</category><category>ioctl</category><category>bsod</category><category>dos</category><category>pool-corruption</category><category>windows</category></item></channel></rss>