PoC Archive PoC Archive

tag

LPE

  • CVE-2026-21508 binary HIGH 7.8

    Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)

    CVE-2026-21508 is a DLL hijacking vulnerability that achieves Session 0 privilege escalation on Windows 11. WUDFHost.exe loads CrossDevice.Streaming.Source.dll from the user-writable path C:\ProgramData\CrossDevice\. By planting a malicious DLL and…

    Patched 2026-08-16
  • CVE-2026-68398 binary HIGH 7.8

    Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)

    CVE-2026-68398 is a use-after-free race condition between PPPoL2TP receive processing and destruction of a bound-but-unattached PPP channel in the Linux kernel. The PPPoX socket and its embedded pppchannel are RCU-safe, but the internal struct channel used by…

    Patched 2026-08-16
  • CVE-2026-23111 binary HIGH 7.8

    Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)

    CVE-2026-23111 is a use-after-free in the Linux nftables subsystem caused by an inverted genmask check in nftmapcatchallactivate(). During transaction abort, the handler skips inactive catchall elements that need reactivation and processes active ones that do…

    Unverified 2026-08-16
  • CVE-2026-53361 binary CRITICAL 9.8

    Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)

    CVE-2026-53361 is a use-after-free in the Linux AFUNIX socket garbage collector triggered via a MSGPEEK race. The GC reclaims in-flight sockets forming unreachable reference cycles, but a concurrent MSGPEEK can take a reference the GC census never counts. The…

    Unverified 2026-08-16
  • CVE-2026-64564 binary HIGH 7.8

    Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)

    CVE-2026-64564 is a use-after-free vulnerability in the Linux kernel SCTP ASCONF DEL-IP processing. When a multihomed SCTP association processes an ASCONF chunk that deletes an IP address, the associated transport structure is freed but a dangling pointer…

    Unverified 2026-08-15
  • CVE-2026-68138 binary HIGH 7.8

    Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)

    CVE-2026-68138 is a race condition in the Linux kernel traffic-control rate-table code that leads to a use-after-free or double-free of struct qdiscratetable. The flower classifier sets TCFPROTOOPSDOITUNLOCKED, allowing RTMNEWTFILTER requests to reach…

    Patched 2026-08-15
  • CVE-2026-64531 binary HIGH 7.8

    Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)

    CVE-2026-64531 is a memory corruption vulnerability in the Linux kernel Open vSwitch (OVS) conntrack subsystem. The exploit, named OVSwrap, uses OVS Generic Netlink operations to corrupt conntrack timeout and labels carrier objects, establishing kernel read…

    Unverified 2026-08-15
  • Bypass of CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks

    ShieldBreak is a 0-day local privilege escalation exploit that bypasses the patch for CVE-2026-50656 (RoguePlanet), achieving SYSTEM-level code execution from an unprivileged user on fully patched Windows 11 and Server 2025 systems. The exploit was released…

    Unpatched 2026-08-11
  • NotCVE-2026-0010 binary HIGH

    Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)

    Barrier 2.4.0 ships a Windows service daemon (barrierd.exe) that runs as LocalSystem and binds a TCP IPC control server on 127.0.0.1:24801 with no authentication. Any local process, regardless of privilege level, can connect to that port and send a…

    Unverified 2026-08-01
  • CVE-2026-49176 binary HIGH 7.8

    Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)

    Windows WalletService — which runs as LocalSystem — resolves the caller's FOLDERIDDocuments known folder while impersonating the calling user, then reverts to the LocalSystem token before opening <Documents>\Wallet\wallet.db. Because the folder resolution…

    Patched 2026-07-27
  • binary HIGH

    LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability

    LegacyHive demonstrates a local privilege-escalation path in Windows user profile hive handling where a low-privileged user can influence how another user's hive is loaded. The PoC modifies hive data and abuses object manager links and an oplock timing window…

    Patched 2026-07-19
  • CVE-2026-43499 binary HIGH 7.8

    Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)

    Nebula Security independently discovered and weaponized a use-after-free in the Linux kernel's rtmutex priority-inheritance cleanup logic, naming it "GhostLock." They describe it as a stack-UAF reachable via ordinary threading/futex calls from any…

    Patched 2026-07-08
  • CVE-2026-29923 binary CRITICAL

    Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923

    pstrip64.sys is a legacy signed kernel driver bundled with EnTech Taiwan PowerStrip that exposes an IOCTL (0x80002008) allowing a calling process to map arbitrary physical memory into its own address space via ZwMapViewOfSection against…

    Unverified 2026-07-05
  • CVE-2026-40369 binary HIGH

    Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)

    This exploit is a local privilege escalation chain against the Windows kernel that abuses a low-level primitive reachable through NtQuerySystemInformation to corrupt a bit near the process's SeDebugPrivilege state in kernel memory, without requiring the…

    Unverified 2026-07-05
  • CVE-2026-20817 binary HIGH

    Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)

    CVE-2026-20817 abuses an ALPC-based elevation primitive in the Windows Error Reporting Service. WerSvc listens on the \WindowsErrorReportingServicePort ALPC port and, upon receiving a specially crafted WERSVCMSG request with the SvcElevatedLaunch message flag…

    Unverified 2026-07-05
  • CVE-2026-21018 binary HIGH

    Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)

    CVE-2026-21018 is an out-of-bounds write in the Samsung system service SveService, which runs as system (UID 1000) and is registered directly via ServiceManager.addService() — bypassing Android's normal signatureOrSystem permission enforcement, so it is…

    Unverified 2026-07-05
  • CVE-2026-3437 binary HIGH

    Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)

    portwell.sys, a legitimately signed driver shipped with Portwell Engineering Toolkits v4.8.2, exposes IOCTL handlers that let any local user-mode process read and write arbitrary physical memory via MmMapIoSpace, with no validation of the caller-supplied…

    Unverified 2026-07-05
  • CVE-2026-43494 binary HIGH

    PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)

    This is a hand-written, dependency-free x86-64 NASM rewrite of the "PinTheft" Linux local privilege escalation exploit (originally published as PinTheft-go). It targets a refcount double-drop in the RDS zerocopy send path (rdsmessagezcopyfromuser()), which is…

    Patched 2026-07-05
  • CVE-2026-41651 binary HIGH

    PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)

    PackageKit's transaction handling in src/pk-transaction.c contains a set of logic flaws that combine into a TOCTOU (time-of-check to time-of-use) race condition, nicknamed "Pack2TheRoot" by the researcher. InstallFiles() overwrites cached transaction…

    Patched 2026-07-05
  • CVE-2026-36981 binary HIGH

    MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)

    MiniTool's pwdrvio.sys kernel driver exposes a write-what-where condition through its IOCTL interface, allowing an unprivileged local attacker to write attacker-controlled data to an attacker-controlled kernel address. The included PoC demonstrates a…

    Patched 2026-07-05
  • CVE-2026-41091 binary HIGH 7.8 KEV

    Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)

    CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Defender caused by improper link resolution (CWE-59) during file operations performed with SYSTEM privileges. By racing a Defender-triggered scan against filesystem oplocks, and then…

    Unpatched 2026-07-05
  • CVE-2026-43499 binary HIGH 7.8

    Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)

    CVE-2026-43499 is a use-after-free in the Linux kernel's removewaiter() function (kernel/locking/rtmutex.c), which is shared between the ordinary rtmutex slow-unlock path and the futex priority-inheritance (PI) proxy-lock rollback path invoked from…

    Patched 2026-07-05
  • CVE-2026-31694 binary HIGH

    Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694

    fuseadddirenttocache() is missing a bounds check when copying a FUSE server-supplied directory entry into the kernel's readdir page-cache. A malicious (or attacker-controlled) FUSE server can return a dirent with namelen = 4095, which serializes to a…

    Patched 2026-07-05
  • CVE-2026-31413 binary CRITICAL

    Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413

    The Linux BPF verifier's maybeforkscalars() forks verifier state when it sees an ARSH followed by AND/OR with a constant. The forked ("pushed") path is generated via pushstack(env, env->insnidx + 1, ...), which skips the ALU instruction on that path and…

    Patched 2026-07-05
  • CVE-2026-28372 binary HIGH 7.4

    GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372

    GNU inetutils telnetd forwards client-controlled environment variables — negotiated via the Telnet NEW-ENVIRON option — to the login(1) process it spawns without adequately sanitizing them. On systems where the installed login (from util-linux) supports a…

    Patched 2026-07-05
  • CVE-2026-45250 binary CRITICAL

    FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)

    kernsetcredcopyinsuppgroups() in sys/kern/kernprot.c uses sizeof(groups) where groups is declared as gidt , so the size expression evaluates to 8 bytes (pointer size) instead of the intended 4 bytes (sizeof(gidt)). When the supplementary-groups count is small…

    Unverified 2026-07-05
  • CVE-2026-7270 binary CRITICAL

    FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)

    An operator-precedence bug in FreeBSD's execargsadjustargs() (present since 2013) computes a memmove size using + consume instead of - consume, causing the copy length to be roughly double the correct value. With a ~265KB argv[0] supplied via a shebang exec,…

    Unverified 2026-07-05
  • CVE-2026-45258 binary CRITICAL

    FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)

    This PoC targets a FreeBSD kernel local privilege escalation reachable through the OSS /dev/dsp audio device driver. By configuring device fragment sizes via ioctl(SNDCTLDSPSETFRAGMENT, ...) and then mmap-ing the device with a crafted negative file offset,…

    Unverified 2026-07-05
  • CVE-2026-31635 binary HIGH

    DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635

    This is a Go re-implementation ("port") of the original C dirtydecrypt PoC, now tracked as its own CVE (CVE-2026-31635). The bug is a missing skbcowdata() call in rxgkdecryptskb(): the krb5enc AEAD used by RxRPC's rxgk security class decrypts skb payload data…

    Patched 2026-07-05
  • CVE-2026-1880 binary MEDIUM

    ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880

    ASUS DriverHub updates drivers by downloading a package, extracting it to C:\ProgramData\ASUS\AsusDriverHub\SupportTemp\<drivername>, and later launching setup.exe from that directory via ShellExecuteExW. Because the driver folder name can be predicted from…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 binary HIGH

    System Informer phsvc Trusted-Host Confused Deputy LPE

    System Informer's privileged helper process phsvc exposes an ALPC API port (\BaseNamedObjects\SiSvcApiPort) with a connect ACL open to Everyone, and authorizes connecting clients purely by checking whether the client's process image is generically…

    Unverified 2026-07-03
  • None assigned as of 2026-07-03 binary HIGH

    AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation

    AnyDesk's local printer IPC worker creates a named pipe (\\.\pipe\adprinterpipe) with an ACL that grants access to Everyone, then accepts a message containing attacker-controlled COM marshaling bytes, unmarshals it into an IUnknown, queries for IStream, and…

    Unverified 2026-07-03
  • CVE-2026-46331 binary HIGH 7.8

    Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)

    CVE-2026-46331 is a local privilege escalation in the Linux kernel's net/sched/actpedit subsystem. The vulnerable function tcfpeditact() computes the writable Copy-on-Write (COW) region using a pre-calculated maximum hint (tcfpoffmaxhint) before the actual…

    Patched 2026-06-30
  • CVE-2026-7574 binary HIGH 8.7

    Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)

    CVE-2026-7574 is a VM image integrity bypass in Anthropic's Claude Desktop Cowork feature (macOS). Before booting the Cowork virtual machine, the application validates only the presence of rootfs.img and its associated version marker (.rootfs.img.origin); it…

    Unverified 2026-06-30
  • CVE-2026-45586 binary HIGH 7.8

    Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)

    CVE-2026-45586 (GreenPlasma) is a Windows CTFMON Elevation of Privilege vulnerability exploiting an arbitrary named section object creation primitive. A standard unprivileged user can create a section object in any directory object writable by SYSTEM, abusing…

    Patched 2026-06-28
  • CVE-2026-43503 binary HIGH 8.8

    DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)

    DirtyClone (CVE-2026-43503, CVSS 8.8) is the fourth member of the DirtyFrag family of Linux kernel local privilege escalation vulnerabilities. Each member shares the same root failure: file-backed page-cache memory is exposed to network packet operations, and…

    Patched 2026-06-28
  • CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)

    CVE-2026-50656 is a High-severity Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, publicly referred to as RoguePlanet. It stems from improper link resolution before file access (CWE-59) — the engine follows attacker-controlled…

    Patched 2026-06-26
  • CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition

    RoguePlanet is a local privilege escalation exploit for Windows 10 and 11 that abuses a race condition in Windows Defender's scan pipeline. The exploit mounts an attacker-controlled ISO image via the VirtualDisk API, plants an EICAR-like trigger file inside…

    Unpatched 2026-06-10
  • CVE-2026-46333 binary HIGH

    ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)

    ssh-keysign-pwn demonstrates a local file-descriptor theft primitive on vulnerable Linux kernels. During process exit, a race window appears after exitmm() but before file descriptors are closed; in that state pidfdgetfd(2) can bypass expected dumpable checks…

    Patched 2026-06-05
  • binary HIGH

    PinTheft: RDS Double-Free → LPE

    PinTheft is a Linux local privilege escalation exploit targeting a double-free in the RDS zerocopy send path (rdsmessagezcopyfromuser()). When a multi-page zerocopy send faults on a later page, the error path drops already-pinned pages, but RDS message…

    Unverified 2026-05-20
  • N/A network CRITICAL

    TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE

    TossUp is a pair of bugs against TerraMaster TOS NAS devices. The primary issue is that Redis 4.0.10 runs as root and listens on 0.0.0.0:6379 with no authentication — despite /etc/redis.conf containing bind 127.0.0.1, the init script starts Redis as…

    Unpatched 2026-05-18
  • N/A binary HIGH

    DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)

    DirtyDecrypt (also called DirtyCBC) is a variant of the CopyFail / DirtyFrag / Fragnesia bug class. rxgkdecryptskb() in net/rxrpc/rxgkcommon.h calls skbtosgvec() followed by cryptokrb5decrypt() without first calling skbcowdata(). The krb5enc AEAD template…

    Unverified 2026-05-18
  • CVE-2025-21756 binary HIGH 7.8

    Linux vsock Use-After-Free VM Escape (CVE-2025-21756)

    CVE-2025-21756 is a use-after-free vulnerability in the Linux kernel's vsock (virtual socket) subsystem. An attacker with code execution inside a virtual machine can exploit this bug to escape the VM boundary and gain root-level code execution on the…

    Patched 2026-05-17
  • CVE-2024-1086 binary HIGH 7.8 KEV Ransomware EPSS 28%

    Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)

    CVE-2024-1086 is a use-after-free vulnerability in the Linux kernel's netfilter nftables subsystem that allows an unprivileged local user to escalate privileges to root. The exploit achieves a 99.4% success rate on KernelCTF images and works universally…

    Patched 2026-05-17
  • CVE-2026-31431 binary HIGH KEV EPSS 100%

    Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)

    Copy Fail (CVE-2026-31431) is a Linux kernel local privilege-escalation vulnerability published by Theori (Xint Code). The provided PoC abuses AFALG AEAD socket operations with crafted parameters and splice() writes to patch privileged executable bytes and…

    Patched 2026-05-17
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    RedSun Privileged File Write (CVE-2026-33825)

    RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…

    Patched 2026-05-15
  • CVE-2020-17103 binary HIGH 7.8 EPSS 27%

    MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)

    MiniPlasma is a fully weaponized Windows LPE that exploits a race condition in cldflrt!HsmOsBlockPlaceholderAccess inside cldflt.sys — the same vulnerability originally discovered by James Forshaw (Google Project Zero) and reported as CVE-2020-17103 in 2020.…

    Patched 2026-05-15
  • CVE-2024-21338 binary HIGH 7.8 KEV Ransomware EPSS 60%

    CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel

    This PoC targets CVE-2024-21338, a Windows local privilege-escalation issue that enables escalation from local administrator context toward kernel-level control. The exploit chain performs token impersonation and then abuses an AppLocker IOCTL handler with…

    Patched 2026-05-15
  • CVE-2026-33825 binary HIGH 7.8 KEV Ransomware

    BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)

    BlueHammer is a Windows local privilege-escalation PoC targeting Defender-associated update and scanning behavior. The exploit orchestrates object-manager symbolic links, directory change notifications, oplocks, RPC-triggered Defender activity, and…

    Patched 2026-05-15
  • CVE-2026-46300 binary HIGH 7.8

    Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)

    CVE-2026-46300 ("Fragnesia") is a universal Linux local privilege escalation vulnerability in the XFRM ESP-in-TCP subsystem. It is a member of the Dirty Frag vulnerability class — a separate bug from the original dirtyfrag — that abuses a logic flaw where the…

    Patched 2026-05-14
  • CVE-2026-43500, CVE-2026-43284 binary CRITICAL 7.8 EPSS 93%

    Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE

    Dirty Frag is a universal Linux Local Privilege Escalation (LPE) vulnerability class discovered by Hyunwoo Kim (@v4bel) that chains two Page Cache Write primitives: the xfrm-ESP Page-Cache Write (CVE-2026-43284) and the RxRPC Page-Cache Write…

    Patched 2026-05-14