<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Local-Privilege-Escalation — PoC Archive</title><link>https://poc.intelseclab.com/tags/local-privilege-escalation/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/local-privilege-escalation/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24294-petitpotam-smb-ntlm-reflection-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24294-petitpotam-smb-ntlm-reflection-lpe/</guid><description>Critical severity — network · CVE-2026-24294 (Microsoft Security Response Center). Status: Weaponized. Affects: Windows Server 2025 (SMB client "arbitrary TCP port" feature). Tags: ntlm-relay, smb, petitpotam, windows-server-2025, local-privilege-escalation, lsass, coercion, impacket.</description><category>network</category><category>Critical</category><category>ntlm-relay</category><category>smb</category><category>petitpotam</category><category>windows-server-2025</category><category>local-privilege-escalation</category><category>lsass</category><category>coercion</category><category>impacket</category></item><item><title>snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3888-snapd-confine-lpe/</guid><description>High severity — binary · CVE-2026-3888. Status: Weaponized. Affects: snapd (snap-confine writable-mimic / systemd-tmpfiles handling). Tags: snapd, snap-confine, linux, local-privilege-escalation, race-condition, systemd-tmpfiles, mount-namespace.</description><category>binary</category><category>High</category><category>snapd</category><category>snap-confine</category><category>linux</category><category>local-privilege-escalation</category><category>race-condition</category><category>systemd-tmpfiles</category><category>mount-namespace</category></item><item><title>FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49417-freebsd-dsp-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49417-freebsd-dsp-kernel-lpe/</guid><description>High severity — binary · CVE-2026-49417. Status: PoC. Affects: FreeBSD kernel — OSS audio driver (/dev/dsp) buffer allocation / thread-stack recycling. Tags: freebsd, kernel, oss, dev-dsp, kernel-stack-leak, rop, smep-bypass, cr4, local-privilege-escalation, c.</description><category>binary</category><category>High</category><category>freebsd</category><category>kernel</category><category>oss</category><category>dev-dsp</category><category>kernel-stack-leak</category><category>rop</category><category>smep-bypass</category><category>cr4</category><category>local-privilege-escalation</category><category>c</category></item><item><title>FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49413-freebsd-linuxulator-atsecure-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49413-freebsd-linuxulator-atsecure-lpe/</guid><description>High severity — binary · CVE-2026-49413. Status: PoC. Affects: FreeBSD Linux compatibility layer ("Linuxulator", linux/linux64 kernel module) executing Linux setuid-root binaries under /compat/linux/. Tags: freebsd, linuxulator, at_secure, ld_preload, setuid, local-privilege-escalation, c.</description><category>binary</category><category>High</category><category>freebsd</category><category>linuxulator</category><category>at_secure</category><category>ld_preload</category><category>setuid</category><category>local-privilege-escalation</category><category>c</category></item><item><title>Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-24018-forticlient-symlink-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-24018-forticlient-symlink-lpe/</guid><description>High severity — binary · CVE-2026-24018. Status: Weaponized. Affects: Fortinet FortiClientLinux. Tags: forticlient, linux, symlink-following, local-privilege-escalation, setuid, shared-object-injection, vpn-config, cwe-61.</description><category>binary</category><category>High</category><category>forticlient</category><category>linux</category><category>symlink-following</category><category>local-privilege-escalation</category><category>setuid</category><category>shared-object-injection</category><category>vpn-config</category><category>cwe-61</category></item><item><title>ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</guid><description>Medium severity — binary · CVE-2026-1880. Status: PoC. Affects: ASUS DriverHub (driver update utility). Tags: windows, toctou, race-condition, lpe, driverhub, asus, local-privilege-escalation, shellexecute.</description><category>binary</category><category>Medium</category><category>windows</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>driverhub</category><category>asus</category><category>local-privilege-escalation</category><category>shellexecute</category></item><item><title>Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24072-apache-httpd-ap-expr-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-24072-apache-httpd-ap-expr-lpe/</guid><description>Medium severity — web · CVE-2026-24072. Status: PoC. Affects: Apache HTTP Server (httpd). Tags: apache-httpd, mod_rewrite, ap_expr, htaccess, local-privilege-escalation, arbitrary-file-read, information-disclosure, cwe-668.</description><category>web</category><category>Medium</category><category>apache-httpd</category><category>mod_rewrite</category><category>ap_expr</category><category>htaccess</category><category>local-privilege-escalation</category><category>arbitrary-file-read</category><category>information-disclosure</category><category>cwe-668</category></item><item><title>System Informer phsvc Trusted-Host Confused Deputy LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_systeminformer-phsvc-trusted-host-lpe/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_systeminformer-phsvc-trusted-host-lpe/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: System Informer (Process Hacker successor), phsvc helper process. Tags: windows, system-informer, process-hacker, lpe, confused-deputy, alpc, phsvc, authenticode, local-privilege-escalation.</description><category>binary</category><category>High</category><category>windows</category><category>system-informer</category><category>process-hacker</category><category>lpe</category><category>confused-deputy</category><category>alpc</category><category>phsvc</category><category>authenticode</category><category>local-privilege-escalation</category></item><item><title>LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-30_litespeed-user-end-cpanel-plugin-privesc/</link><pubDate>Sat, 30 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-30_litespeed-user-end-cpanel-plugin-privesc/</guid><description>High severity — web · CVE-2026-48172. Status: Patched. Affects: LiteSpeed cPanel Plugin. Tags: local-privilege-escalation, cPanel, LiteSpeed, symlink, archive-extraction.</description><category>web</category><category>High</category><category>local-privilege-escalation</category><category>cPanel</category><category>LiteSpeed</category><category>symlink</category><category>archive-extraction</category></item></channel></rss>