PoC Archive PoC Archive

tag

Local-User

  • CVE-2020-17103 binary HIGH 7.8 EPSS 27%

    MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)

    MiniPlasma is a fully weaponized Windows LPE that exploits a race condition in cldflrt!HsmOsBlockPlaceholderAccess inside cldflt.sys — the same vulnerability originally discovered by James Forshaw (Google Project Zero) and reported as CVE-2020-17103 in 2020.…

    Patched 2026-05-15
  • CVE-2024-21338 binary HIGH 7.8 KEV Ransomware EPSS 60%

    CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel

    This PoC targets CVE-2024-21338, a Windows local privilege-escalation issue that enables escalation from local administrator context toward kernel-level control. The exploit chain performs token impersonation and then abuses an AppLocker IOCTL handler with…

    Patched 2026-05-15
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)

    BlueHammer is a Windows local privilege-escalation PoC targeting Defender-associated update and scanning behavior. The exploit orchestrates object-manager symbolic links, directory change notifications, oplocks, RPC-triggered Defender activity, and…

    Patched 2026-05-15