<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Local — PoC Archive</title><link>https://poc.intelseclab.com/tags/local/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 01 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/local/index.xml" rel="self" type="application/rss+xml"/><item><title>Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</guid><description>High severity — binary · NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier). Status: Unpatched — Barrier is unmaintained with no vendor fix; patched successor Deskflow covers the same issue via CVE-2026-41477 / GHSA-6rx5-g478-775c. Affects: Barrier (debauchee), Windows service daemon barrierd.exe. Tags: barrier, barrierd, windows, ipc, tcp-24801, unauthenticated, lpe, privilege-escalation, system, cwe-306, local.</description><category>binary</category><category>High</category><category>barrier</category><category>barrierd</category><category>windows</category><category>ipc</category><category>tcp-24801</category><category>unauthenticated</category><category>lpe</category><category>privilege-escalation</category><category>system</category><category>cwe-306</category><category>local</category></item><item><title>Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-49176. Status: Weaponized — SYSTEM shell confirmed against a real, vulnerable Windows 11 build. Affects: Windows WalletService (Windows.ApplicationModel.Wallet WinRT API, backed by an ESE/Jet Blue database under the caller's Documents\Wallet folder). Tags: windows, walletservice, lpe, privilege-escalation, ese, extensible-storage-engine, known-folder-redirection, persisted-callback, local.</description><category>binary</category><category>High</category><category>windows</category><category>walletservice</category><category>lpe</category><category>privilege-escalation</category><category>ese</category><category>extensible-storage-engine</category><category>known-folder-redirection</category><category>persisted-callback</category><category>local</category></item><item><title>GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</guid><description>High severity — binary · N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27). Status: Unpatched. Affects: Windows Recovery Environment (WinRE) — Microsoft Defender Offline Scan launch path (ReAgent.xml scheduled operation). Tags: windows, bitlocker, winre, defender, offline-scan, trust-boundary-bypass, zero-day, unpatched, physical-access, local.</description><category>binary</category><category>High</category><category>windows</category><category>bitlocker</category><category>winre</category><category>defender</category><category>offline-scan</category><category>trust-boundary-bypass</category><category>zero-day</category><category>unpatched</category><category>physical-access</category><category>local</category></item><item><title>Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499 (aka "GhostLock"). Status: Weaponized (per Nebula Security disclosure); no exploit code mirrored into this repo, see Notes. Affects: Linux kernel — rtmutex priority-inheritance (futex-PI) subsystem, CONFIG_FUTEX_PI. Tags: linux-kernel, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, container-escape, kernelctf, ghostlock.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>container-escape</category><category>kernelctf</category><category>ghostlock</category></item><item><title>Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</guid><description>High severity — binary · CVE-2026-40369. Status: PoC. Affects: Windows kernel (ntoskrnl.exe). Tags: windows, kernel, lpe, privilege-escalation, token-stealing, sedebugprivilege, ntoskrnl, local.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>token-stealing</category><category>sedebugprivilege</category><category>ntoskrnl</category><category>local</category></item><item><title>PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</guid><description>High severity — binary · CVE-2026-43494. Status: PoC. Affects: Linux kernel (RDS zerocopy send path + io_uring fixed buffers). Tags: linux-kernel, lpe, double-free, use-after-free, rds, io_uring, page-cache-overwrite, x86_64, nasm, asm, local, root-shell.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>double-free</category><category>use-after-free</category><category>rds</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>nasm</category><category>asm</category><category>local</category><category>root-shell</category></item><item><title>Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499. Status: PoC. Affects: Linux kernel — kernel/locking/rtmutex.c, futex-PI subsystem (futex_requeue() / rt_mutex_start_proxy_lock()). Tags: linux-kernel, android, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, kernel-panic, ndk.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>android</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>kernel-panic</category><category>ndk</category></item><item><title>RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Weaponized. Affects: Microsoft Windows Defender / Windows Error Reporting Task Scheduler. Tags: LPE, Windows Defender, race-condition, TOCTOU, ISO-mount, VirtualDisk, Task-Scheduler, WER, EICAR, SYSTEM-shell, Windows-10, Windows-11, local.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>race-condition</category><category>TOCTOU</category><category>ISO-mount</category><category>VirtualDisk</category><category>Task-Scheduler</category><category>WER</category><category>EICAR</category><category>SYSTEM-shell</category><category>Windows-10</category><category>Windows-11</category><category>local</category></item><item><title>Notepad++ &lt;= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</guid><description>High severity (CVSS 5) — binary · CVE-2026-48770, CVE-2026-48778, CVE-2026-48800. Status: Patched. Affects: Notepad++. Tags: Notepad++, Windows, OOB-read, DoS, command-injection, config.xml, shortcuts.xml, local.</description><category>binary</category><category>High</category><category>Notepad++</category><category>Windows</category><category>OOB-read</category><category>DoS</category><category>command-injection</category><category>config.xml</category><category>shortcuts.xml</category><category>local</category></item><item><title>PinTheft: RDS Double-Free → LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</guid><description>High severity — binary. Status: Weaponized. Affects: Linux kernel (RDS subsystem + io_uring). Tags: LPE, double-free, use-after-free, Linux kernel, RDS, io_uring, page-cache-overwrite, x86_64, local.</description><category>binary</category><category>High</category><category>LPE</category><category>double-free</category><category>use-after-free</category><category>Linux kernel</category><category>RDS</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>local</category></item><item><title>Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_copy-fail-cve-2026-31431/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_copy-fail-cve-2026-31431/</guid><description>High severity — binary · CVE-2026-31431. Status: Weaponized. Affects: Linux kernel (crypto / AF_ALG AEAD path). Tags: LPE, Linux kernel, AF_ALG, authenc, splice, local, Python.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>AF_ALG</category><category>authenc</category><category>splice</category><category>local</category><category>Python</category></item><item><title>QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_qemutiny-memory-corruption/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_qemutiny-memory-corruption/</guid><description>Critical severity — binary. Status: Weaponized. Affects: QEMU CXL Type-3 device emulation (hw/cxl/cxl-mailbox-utils.c). Tags: QEMU, CXL, memory-corruption, OOB-read, OOB-write, guest-to-host-escape, local, root-in-guest.</description><category>binary</category><category>Critical</category><category>QEMU</category><category>CXL</category><category>memory-corruption</category><category>OOB-read</category><category>OOB-write</category><category>guest-to-host-escape</category><category>local</category><category>root-in-guest</category></item><item><title>Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-rxrpc-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-rxrpc-lpe/</guid><description>Critical severity (CVSS 7.8) — binary · CVE-2026-43500, CVE-2026-43284. Status: Weaponized. Affects: Linux kernel. Tags: LPE, Linux kernel, page-cache, xfrm, RxRPC, local, unauthenticated, Dirty Pipe variant.</description><category>binary</category><category>Critical</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>xfrm</category><category>RxRPC</category><category>local</category><category>unauthenticated</category><category>Dirty Pipe variant</category></item></channel></rss>