<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>LPE — PoC Archive</title><link>https://poc.intelseclab.com/tags/lpe/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/lpe/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-21508. Status: Patched. Affects: Microsoft Windows Media Player / WUDFHost.exe. Tags: windows, dll-hijack, lpe, privilege-escalation, media-player, wudfhost, session0, com-hijack, CVE-2026-21508.</description><category>binary</category><category>High</category><category>windows</category><category>dll-hijack</category><category>lpe</category><category>privilege-escalation</category><category>media-player</category><category>wudfhost</category><category>session0</category><category>com-hijack</category><category>CVE-2026-21508</category></item><item><title>Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-68398-ubuntu-pppol2tp-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68398. Status: Patched. Affects: Linux Kernel (PPPoL2TP subsystem). Tags: linux, kernel, ubuntu, pppol2tp, l2tp, ppp, uaf, use-after-free, race-condition, lpe, privilege-escalation, kaslr-bypass, apparmor-bypass, suid, heap-spray, kmalloc-256, CVE-2026-68398.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>ubuntu</category><category>pppol2tp</category><category>l2tp</category><category>ppp</category><category>uaf</category><category>use-after-free</category><category>race-condition</category><category>lpe</category><category>privilege-escalation</category><category>kaslr-bypass</category><category>apparmor-bypass</category><category>suid</category><category>heap-spray</category><category>kmalloc-256</category><category>CVE-2026-68398</category></item><item><title>Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-23111-nftables-catchall-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-23111. Status: Patched. Affects: Linux kernel (nf_tables subsystem). Tags: linux, kernel, nftables, nf-tables, uaf, catchall, lpe, privilege-escalation, slab-spray, kaslr-bypass, rop, namespace, CVE-2026-23111.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>nftables</category><category>nf-tables</category><category>uaf</category><category>catchall</category><category>lpe</category><category>privilege-escalation</category><category>slab-spray</category><category>kaslr-bypass</category><category>rop</category><category>namespace</category><category>CVE-2026-23111</category></item><item><title>Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-53361-afunix-gc-peek-uaf-container-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-53361. Status: Patched. Affects: Linux Kernel (AF_UNIX socket garbage collector). Tags: linux, kernel, af-unix, garbage-collector, msg-peek, uaf, container-escape, lpe, slub, dirty-pagetable, CVE-2026-53361.</description><category>binary</category><category>Critical</category><category>linux</category><category>kernel</category><category>af-unix</category><category>garbage-collector</category><category>msg-peek</category><category>uaf</category><category>container-escape</category><category>lpe</category><category>slub</category><category>dirty-pagetable</category><category>CVE-2026-53361</category></item><item><title>Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64564-sctphantom-sctp-asconf-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64564. Status: Patched. Affects: Linux kernel, SCTP (Stream Control Transmission Protocol) ASCONF subsystem. Tags: linux, kernel, lpe, sctp, use-after-free, asconf, del-ip, heap-spray, packet-tx-ring, kaslr-bypass, credential-overwrite, debian, CWE-416, CVE-2026-64564.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>sctp</category><category>use-after-free</category><category>asconf</category><category>del-ip</category><category>heap-spray</category><category>packet-tx-ring</category><category>kaslr-bypass</category><category>credential-overwrite</category><category>debian</category><category>CWE-416</category><category>CVE-2026-64564</category></item><item><title>Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-68138-linux-qdisc-ratetable-race-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-68138. Status: Patched. Affects: Linux kernel, traffic-control qdisc rate-table subsystem (qdisc_get_rtab / qdisc_put_rtab). Tags: linux, kernel, lpe, race-condition, use-after-free, qdisc, traffic-control, flower, bpf, pipe, page-cache, modprobe, CWE-362, CWE-416, CVE-2026-68138.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>race-condition</category><category>use-after-free</category><category>qdisc</category><category>traffic-control</category><category>flower</category><category>bpf</category><category>pipe</category><category>page-cache</category><category>modprobe</category><category>CWE-362</category><category>CWE-416</category><category>CVE-2026-68138</category></item><item><title>Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-15_cve-2026-64531-ovswrap-linux-ovs-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-64531. Status: Patched. Affects: Linux kernel, Open vSwitch (OVS) kernel module, conntrack subsystem. Tags: linux, kernel, lpe, openvswitch, ovs, conntrack, netlink, memory-corruption, sudoers, CVE-2026-64531.</description><category>binary</category><category>High</category><category>linux</category><category>kernel</category><category>lpe</category><category>openvswitch</category><category>ovs</category><category>conntrack</category><category>netlink</category><category>memory-corruption</category><category>sudoers</category><category>CVE-2026-64531</category></item><item><title>Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</guid><description>High severity (CVSS 7.8) — binary · Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11. Status: Unpatched. Affects: Microsoft Windows Defender (Antimalware Service Executable / MsMpEng.exe), threat remediation subsystem. Tags: windows, windows-defender, lpe, privilege-escalation, 0day, patch-bypass, cloud-files, cfapi, object-manager, symlink, wer, dll-sideload, CWE-59, CWE-426, microsoft, rogueplanet, shieldbreak.</description><category>binary</category><category>High</category><category>windows</category><category>windows-defender</category><category>lpe</category><category>privilege-escalation</category><category>0day</category><category>patch-bypass</category><category>cloud-files</category><category>cfapi</category><category>object-manager</category><category>symlink</category><category>wer</category><category>dll-sideload</category><category>CWE-59</category><category>CWE-426</category><category>microsoft</category><category>rogueplanet</category><category>shieldbreak</category></item><item><title>Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</guid><description>High severity — binary · NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier). Status: Unpatched — Barrier is unmaintained with no vendor fix; patched successor Deskflow covers the same issue via CVE-2026-41477 / GHSA-6rx5-g478-775c. Affects: Barrier (debauchee), Windows service daemon barrierd.exe. Tags: barrier, barrierd, windows, ipc, tcp-24801, unauthenticated, lpe, privilege-escalation, system, cwe-306, local.</description><category>binary</category><category>High</category><category>barrier</category><category>barrierd</category><category>windows</category><category>ipc</category><category>tcp-24801</category><category>unauthenticated</category><category>lpe</category><category>privilege-escalation</category><category>system</category><category>cwe-306</category><category>local</category></item><item><title>Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-49176. Status: Weaponized — SYSTEM shell confirmed against a real, vulnerable Windows 11 build. Affects: Windows WalletService (Windows.ApplicationModel.Wallet WinRT API, backed by an ESE/Jet Blue database under the caller's Documents\Wallet folder). Tags: windows, walletservice, lpe, privilege-escalation, ese, extensible-storage-engine, known-folder-redirection, persisted-callback, local.</description><category>binary</category><category>High</category><category>windows</category><category>walletservice</category><category>lpe</category><category>privilege-escalation</category><category>ese</category><category>extensible-storage-engine</category><category>known-folder-redirection</category><category>persisted-callback</category><category>local</category></item><item><title>LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-19_legacyhive-user-profile-service-hive-load-lpe/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-19_legacyhive-user-profile-service-hive-load-lpe/</guid><description>High severity — binary. Status: Weaponized. Affects: Microsoft Windows user profile service / registry hive loading path. Tags: windows, lpe, user-profile-service, registry-hive, usrclass.dat, oplock, symbolic-link.</description><category>binary</category><category>High</category><category>windows</category><category>lpe</category><category>user-profile-service</category><category>registry-hive</category><category>usrclass.dat</category><category>oplock</category><category>symbolic-link</category></item><item><title>Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-08_cve-2026-43499-ghostlock-nebula-security/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499 (aka "GhostLock"). Status: Weaponized (per Nebula Security disclosure); no exploit code mirrored into this repo, see Notes. Affects: Linux kernel — rtmutex priority-inheritance (futex-PI) subsystem, CONFIG_FUTEX_PI. Tags: linux-kernel, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, container-escape, kernelctf, ghostlock.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>container-escape</category><category>kernelctf</category><category>ghostlock</category></item><item><title>Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-29923-pstrip64-driver-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-29923-pstrip64-driver-lpe/</guid><description>Critical severity — binary · CVE-2026-29923. Status: Weaponized. Affects: pstrip64.sys kernel driver (EnTech Taiwan PowerStrip, up to version 3.90.736). Tags: byovd, windows-kernel, lpe, physical-memory, eprocess, token-theft, driver, ioctl.</description><category>binary</category><category>Critical</category><category>byovd</category><category>windows-kernel</category><category>lpe</category><category>physical-memory</category><category>eprocess</category><category>token-theft</category><category>driver</category><category>ioctl</category></item><item><title>Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</guid><description>High severity — binary · CVE-2026-40369. Status: PoC. Affects: Windows kernel (ntoskrnl.exe). Tags: windows, kernel, lpe, privilege-escalation, token-stealing, sedebugprivilege, ntoskrnl, local.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>token-stealing</category><category>sedebugprivilege</category><category>ntoskrnl</category><category>local</category></item><item><title>Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20817-windows-wer-alpc-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20817-windows-wer-alpc-lpe/</guid><description>High severity — binary · CVE-2026-20817. Status: PoC. Affects: Windows Error Reporting Service (WerSvc). Tags: windows, wersvc, alpc, lpe, privilege-escalation, ntdll, system32, native-cpp.</description><category>binary</category><category>High</category><category>windows</category><category>wersvc</category><category>alpc</category><category>lpe</category><category>privilege-escalation</category><category>ntdll</category><category>system32</category><category>native-cpp</category></item><item><title>Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21018-samsung-sveservice-oob-write-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-21018-samsung-sveservice-oob-write-lpe/</guid><description>High severity — binary · CVE-2026-21018 (Samsung SVE-2026-0478, SMR May 2026). Status: PoC. Affects: Samsung SveService (com.sec.sve) system service and its libsvejni.so native library. Tags: android, samsung, binder, native, out-of-bounds-write, jni, lpe, memcpy, memset.</description><category>binary</category><category>High</category><category>android</category><category>samsung</category><category>binder</category><category>native</category><category>out-of-bounds-write</category><category>jni</category><category>lpe</category><category>memcpy</category><category>memset</category></item><item><title>Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3437-portwell-sys-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3437-portwell-sys-lpe/</guid><description>High severity — binary · CVE-2026-3437. Status: PoC. Affects: Portwell Engineering Toolkits driver, portwell.sys (v4.8.2). Tags: byovd, windows-driver, kernel, lpe, physical-memory, ioctl, privilege-escalation.</description><category>binary</category><category>High</category><category>byovd</category><category>windows-driver</category><category>kernel</category><category>lpe</category><category>physical-memory</category><category>ioctl</category><category>privilege-escalation</category></item><item><title>PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43494-pintheft-nasm-kernel-lpe/</guid><description>High severity — binary · CVE-2026-43494. Status: PoC. Affects: Linux kernel (RDS zerocopy send path + io_uring fixed buffers). Tags: linux-kernel, lpe, double-free, use-after-free, rds, io_uring, page-cache-overwrite, x86_64, nasm, asm, local, root-shell.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>double-free</category><category>use-after-free</category><category>rds</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>nasm</category><category>asm</category><category>local</category><category>root-shell</category></item><item><title>PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</guid><description>High severity — binary · CVE-2026-41651. Status: PoC. Affects: PackageKit daemon (packagekitd). Tags: linux, packagekit, toctou, race-condition, lpe, polkit, privilege-escalation, dbus.</description><category>binary</category><category>High</category><category>linux</category><category>packagekit</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>polkit</category><category>privilege-escalation</category><category>dbus</category></item><item><title>MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36981-minitool-kernel-driver-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36981-minitool-kernel-driver-lpe/</guid><description>High severity — binary · CVE-2026-36981. Status: PoC. Affects: MiniTool pwdrvio.sys kernel driver. Tags: minitool, kernel-driver, write-what-where, lpe, arbitrary-kernel-write, windows.</description><category>binary</category><category>High</category><category>minitool</category><category>kernel-driver</category><category>write-what-where</category><category>lpe</category><category>arbitrary-kernel-write</category><category>windows</category></item><item><title>Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41091-defender-link-following-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41091-defender-link-following-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-41091. Status: Weaponized. Affects: Microsoft Defender / Microsoft Malware Protection Engine. Tags: windows, microsoft-defender, link-following, cwe-59, cloud-files-api, ntfs-junction, oplock, privilege-escalation, lpe.</description><category>binary</category><category>High</category><category>windows</category><category>microsoft-defender</category><category>link-following</category><category>cwe-59</category><category>cloud-files-api</category><category>ntfs-junction</category><category>oplock</category><category>privilege-escalation</category><category>lpe</category></item><item><title>Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-43499-rtmutex-remove-waiter-uaf/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-43499. Status: PoC. Affects: Linux kernel — kernel/locking/rtmutex.c, futex-PI subsystem (futex_requeue() / rt_mutex_start_proxy_lock()). Tags: linux-kernel, android, use-after-free, futex, rtmutex, priority-inheritance, lpe, local, kernel-panic, ndk.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>android</category><category>use-after-free</category><category>futex</category><category>rtmutex</category><category>priority-inheritance</category><category>lpe</category><category>local</category><category>kernel-panic</category><category>ndk</category></item><item><title>Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</guid><description>High severity — binary · CVE-2026-31694. Status: Weaponized. Affects: Linux kernel — fs/fuse/readdir.c (fuse_add_dirent_to_cache()). Tags: linux-kernel, fuse, oob-write, page-cache, lpe, groom, unprivileged, qemu-kvm.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>fuse</category><category>oob-write</category><category>page-cache</category><category>lpe</category><category>groom</category><category>unprivileged</category><category>qemu-kvm</category></item><item><title>Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31413-bpf-verifier-container-escape/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31413-bpf-verifier-container-escape/</guid><description>Critical severity — binary · CVE-2026-31413. Status: Weaponized. Affects: Linux kernel — BPF verifier (maybe_fork_scalars()). Tags: linux-kernel, ebpf, bpf-verifier, container-escape, modprobe-path, gke, lpe, vtable-hijack.</description><category>binary</category><category>Critical</category><category>linux-kernel</category><category>ebpf</category><category>bpf-verifier</category><category>container-escape</category><category>modprobe-path</category><category>gke</category><category>lpe</category><category>vtable-hijack</category></item><item><title>GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-28372-telnetd-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-28372-telnetd-lpe/</guid><description>High severity (CVSS 7.4) — binary · CVE-2026-28372. Status: PoC. Affects: GNU inetutils telnetd. Tags: telnetd, inetutils, lpe, new-environ, login-noauth, authentication-bypass, privilege-escalation, util-linux.</description><category>binary</category><category>High</category><category>telnetd</category><category>inetutils</category><category>lpe</category><category>new-environ</category><category>login-noauth</category><category>authentication-bypass</category><category>privilege-escalation</category><category>util-linux</category></item><item><title>FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45250-setcred-freebsd-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45250-setcred-freebsd-lpe/</guid><description>Critical severity — binary · CVE-2026-45250. Status: PoC. Affects: FreeBSD kernel — setcred(2) system call (sys/kern/kern_prot.c). Tags: freebsd, kernel, lpe, privilege-escalation, stack-overflow, setcred, smap-bypass, smep-bypass, zfs, kernel-exploit.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>stack-overflow</category><category>setcred</category><category>smap-bypass</category><category>smep-bypass</category><category>zfs</category><category>kernel-exploit</category></item><item><title>FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-7270-freebsd-execargs-oob-memmove-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-7270-freebsd-execargs-oob-memmove-lpe/</guid><description>Critical severity — binary · CVE-2026-7270. Status: Weaponized. Affects: FreeBSD kernel — sys/kern/kern_exec.c exec_args_adjust_args(). Tags: freebsd, kernel, lpe, memmove, oob, race-condition, ld_preload, sshd, cwe-190, cwe-787.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>memmove</category><category>oob</category><category>race-condition</category><category>ld_preload</category><category>sshd</category><category>cwe-190</category><category>cwe-787</category></item><item><title>FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45258-1day-lpe-exploit/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-45258-1day-lpe-exploit/</guid><description>Critical severity — binary · CVE-2026-45258. Status: PoC. Affects: FreeBSD kernel (OSS//dev/dsp sound driver mmap handling). Tags: freebsd, kernel, lpe, privilege-escalation, oss, dev-dsp, mmap, setuid, 1day.</description><category>binary</category><category>Critical</category><category>freebsd</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>oss</category><category>dev-dsp</category><category>mmap</category><category>setuid</category><category>1day</category></item><item><title>DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</guid><description>High severity — binary · CVE-2026-31635. Status: Weaponized. Affects: Linux kernel — net/rxrpc/rxgk_common.h (rxgk_decrypt_skb()). Tags: linux-kernel, lpe, rxrpc, rxgk, page-cache, dirty-pipe-variant, splice, golang, unprivileged.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>rxrpc</category><category>rxgk</category><category>page-cache</category><category>dirty-pipe-variant</category><category>splice</category><category>golang</category><category>unprivileged</category></item><item><title>ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</guid><description>Medium severity — binary · CVE-2026-1880. Status: PoC. Affects: ASUS DriverHub (driver update utility). Tags: windows, toctou, race-condition, lpe, driverhub, asus, local-privilege-escalation, shellexecute.</description><category>binary</category><category>Medium</category><category>windows</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>driverhub</category><category>asus</category><category>local-privilege-escalation</category><category>shellexecute</category></item><item><title>System Informer phsvc Trusted-Host Confused Deputy LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_systeminformer-phsvc-trusted-host-lpe/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_systeminformer-phsvc-trusted-host-lpe/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: System Informer (Process Hacker successor), phsvc helper process. Tags: windows, system-informer, process-hacker, lpe, confused-deputy, alpc, phsvc, authenticode, local-privilege-escalation.</description><category>binary</category><category>High</category><category>windows</category><category>system-informer</category><category>process-hacker</category><category>lpe</category><category>confused-deputy</category><category>alpc</category><category>phsvc</category><category>authenticode</category><category>local-privilege-escalation</category></item><item><title>AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_anydesk-printer-pipe-com-impersonation-lpe/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_anydesk-printer-pipe-com-impersonation-lpe/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: AnyDesk for Windows 9.7.6. Tags: anydesk, windows, privilege-escalation, com-impersonation, named-pipe, local-service, lpe, ipc.</description><category>binary</category><category>High</category><category>anydesk</category><category>windows</category><category>privilege-escalation</category><category>com-impersonation</category><category>named-pipe</category><category>local-service</category><category>lpe</category><category>ipc</category></item><item><title>Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-46331-linux-act-pedit-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46331. Status: PoC. Affects: Linux Kernel — net/sched/act_pedit (traffic control packet editing). Tags: LPE, Linux kernel, COW, page-cache, act_pedit, tc, netlink, traffic-control, privilege-escalation, userns, C, DirtyFrag.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>COW</category><category>page-cache</category><category>act_pedit</category><category>tc</category><category>netlink</category><category>traffic-control</category><category>privilege-escalation</category><category>userns</category><category>C</category><category>DirtyFrag</category></item><item><title>Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-7574-claude-desktop-cowork-vm-bypass/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-7574-claude-desktop-cowork-vm-bypass/</guid><description>High severity (CVSS 8.7) — binary · CVE-2026-7574. Status: PoC. Affects: Anthropic Claude Desktop — Cowork feature. Tags: LPE, persistence, VM-integrity, rootfs, Claude, AI-application, macOS, ext4, integrity-bypass, Shell.</description><category>binary</category><category>High</category><category>LPE</category><category>persistence</category><category>VM-integrity</category><category>rootfs</category><category>Claude</category><category>AI-application</category><category>macOS</category><category>ext4</category><category>integrity-bypass</category><category>Shell</category></item><item><title>Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-45586. Status: PoC. Affects: Windows Collaborative Translation Framework (CTFMON service). Tags: LPE, EoP, Windows, CTFMON, section-object, object-directory, link-following, zero-day, CTF-challenge, Windows-11, Windows-2022, Windows-2026, incomplete-poc.</description><category>binary</category><category>High</category><category>LPE</category><category>EoP</category><category>Windows</category><category>CTFMON</category><category>section-object</category><category>object-directory</category><category>link-following</category><category>zero-day</category><category>CTF-challenge</category><category>Windows-11</category><category>Windows-2022</category><category>Windows-2026</category><category>incomplete-poc</category></item><item><title>DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_dirtyclone-cve-2026-43503-lpe/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-43503. Status: Weaponized. Affects: Linux kernel (netfilter TEE / __pskb_copy_fclone()). Tags: LPE, Linux kernel, netfilter, TEE, IPsec, XFRM, page-cache, file-backed memory, DirtyFrag, skb, privilege escalation, C, in-the-wild.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>netfilter</category><category>TEE</category><category>IPsec</category><category>XFRM</category><category>page-cache</category><category>file-backed memory</category><category>DirtyFrag</category><category>skb</category><category>privilege escalation</category><category>C</category><category>in-the-wild</category></item><item><title>CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-26_cve-2026-50656-rogueplanet-checker/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-26_cve-2026-50656-rogueplanet-checker/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Researched. Affects: Microsoft Malware Protection Engine (mpengine.dll, MsMpEng.exe). Tags: LPE, Windows Defender, TOCTOU, symlink, reparse-point, junction, CWE-59, checker, detection, non-destructive, MsMpEng.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>TOCTOU</category><category>symlink</category><category>reparse-point</category><category>junction</category><category>CWE-59</category><category>checker</category><category>detection</category><category>non-destructive</category><category>MsMpEng</category></item><item><title>RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Weaponized. Affects: Microsoft Windows Defender / Windows Error Reporting Task Scheduler. Tags: LPE, Windows Defender, race-condition, TOCTOU, ISO-mount, VirtualDisk, Task-Scheduler, WER, EICAR, SYSTEM-shell, Windows-10, Windows-11, local.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>race-condition</category><category>TOCTOU</category><category>ISO-mount</category><category>VirtualDisk</category><category>Task-Scheduler</category><category>WER</category><category>EICAR</category><category>SYSTEM-shell</category><category>Windows-10</category><category>Windows-11</category><category>local</category></item><item><title>ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-05_ssh-keysign-pwn/</link><pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-05_ssh-keysign-pwn/</guid><description>High severity — binary · CVE-2026-46333. Status: Patched. Affects: Linux kernel plus privileged userland binaries (ssh-keysign, chage). Tags: LPE, Linux kernel, pidfd_getfd, ptrace, ssh-keysign, chage, fd-theft.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>pidfd_getfd</category><category>ptrace</category><category>ssh-keysign</category><category>chage</category><category>fd-theft</category></item><item><title>PinTheft: RDS Double-Free → LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</link><pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-20_pintheft-rds-double-free/</guid><description>High severity — binary. Status: Weaponized. Affects: Linux kernel (RDS subsystem + io_uring). Tags: LPE, double-free, use-after-free, Linux kernel, RDS, io_uring, page-cache-overwrite, x86_64, local.</description><category>binary</category><category>High</category><category>LPE</category><category>double-free</category><category>use-after-free</category><category>Linux kernel</category><category>RDS</category><category>io_uring</category><category>page-cache-overwrite</category><category>x86_64</category><category>local</category></item><item><title>TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE</title><link>https://poc.intelseclab.com/pocs/network/2026-05-18_tossup-terramaster-redis-rce/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-18_tossup-terramaster-redis-rce/</guid><description>Critical severity — network · N/A (vendor confirmed TOS4 is EOL; no fix planned). Status: Weaponized. Affects: TerraMaster TOS3_A1.0 4.2.41, Redis 4.0.10. Tags: RCE, unauthenticated, Redis, TerraMaster, NAS, AArch64, root, module-loading, replication-abuse, NFS, no_root_squash, LPE, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Redis</category><category>TerraMaster</category><category>NAS</category><category>AArch64</category><category>root</category><category>module-loading</category><category>replication-abuse</category><category>NFS</category><category>no_root_squash</category><category>LPE</category><category>network</category></item><item><title>DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</guid><description>High severity — binary · N/A (reported as duplicate by kernel maintainers; patched on mainline). Status: Weaponized. Affects: Linux kernel — net/rxrpc (rxgk_decrypt_skb). Tags: LPE, Linux kernel, page-cache, rxgk, RxRPC, COW, write-primitive, unprivileged, Dirty-Pipe-variant, splice, MSG_SPLICE_PAGES.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>rxgk</category><category>RxRPC</category><category>COW</category><category>write-primitive</category><category>unprivileged</category><category>Dirty-Pipe-variant</category><category>splice</category><category>MSG_SPLICE_PAGES</category></item><item><title>Linux vsock Use-After-Free VM Escape (CVE-2025-21756)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-vsock-vm-escape/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-vsock-vm-escape/</guid><description>High severity (CVSS 7.8) — binary · CVE-2025-21756. Status: Weaponized. Affects: Linux kernel (vsock / virtual socket subsystem). Tags: UAF, Linux kernel, vsock, VM escape, container escape, virtualization, LPE, x64.</description><category>binary</category><category>High</category><category>UAF</category><category>Linux kernel</category><category>vsock</category><category>VM escape</category><category>container escape</category><category>virtualization</category><category>LPE</category><category>x64</category></item><item><title>Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_linux-nftables-uaf-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2024-1086. Status: Weaponized. Affects: Linux kernel (netfilter nf_tables subsystem). Tags: LPE, UAF, Linux kernel, nf_tables, netfilter, CISA KEV, ransomware, x64.</description><category>binary</category><category>High</category><category>LPE</category><category>UAF</category><category>Linux kernel</category><category>nf_tables</category><category>netfilter</category><category>CISA KEV</category><category>ransomware</category><category>x64</category></item><item><title>Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_copy-fail-cve-2026-31431/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_copy-fail-cve-2026-31431/</guid><description>High severity — binary · CVE-2026-31431. Status: Weaponized. Affects: Linux kernel (crypto / AF_ALG AEAD path). Tags: LPE, Linux kernel, AF_ALG, authenc, splice, local, Python.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>AF_ALG</category><category>authenc</category><category>splice</category><category>local</category><category>Python</category></item><item><title>RedSun Privileged File Write (CVE-2026-33825)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_redsun-privileged-file-write/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_redsun-privileged-file-write/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-33825. Status: Weaponized. Affects: Microsoft Defender Antivirus (real-time protection) on Windows with Cloud Files APIs. Tags: LPE, privileged-file-write, Windows Defender, Cloud Files API, TOCTOU, file-reparse-point.</description><category>binary</category><category>High</category><category>LPE</category><category>privileged-file-write</category><category>Windows Defender</category><category>Cloud Files API</category><category>TOCTOU</category><category>file-reparse-point</category></item><item><title>MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_miniplasma-cve-2020-17103/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_miniplasma-cve-2020-17103/</guid><description>High severity (CVSS 7.8) — binary · CVE-2020-17103. Status: Weaponized. Affects: Windows Cloud Files Mini Filter Driver (cldflt.sys) / cldapi.dll. Tags: LPE, Windows, cldflt.sys, Cloud Files API, registry-symlink, race-condition, WER-hijack, SYSTEM-shell, local-user.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows</category><category>cldflt.sys</category><category>Cloud Files API</category><category>registry-symlink</category><category>race-condition</category><category>WER-hijack</category><category>SYSTEM-shell</category><category>local-user</category></item><item><title>CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_cve-2024-21338-admin-to-kernel/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_cve-2024-21338-admin-to-kernel/</guid><description>High severity (CVSS 7.8) — binary · CVE-2024-21338. Status: Weaponized. Affects: Microsoft Windows AppLocker driver path (\\Device\\AppID). Tags: LPE, Windows, AppLocker, token-impersonation, HVCI, admin-to-kernel, local-user.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows</category><category>AppLocker</category><category>token-impersonation</category><category>HVCI</category><category>admin-to-kernel</category><category>local-user</category></item><item><title>BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_bluehammer-defender-lpe/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_bluehammer-defender-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-33825. Status: Weaponized. Affects: Microsoft Defender Antivirus update/scan workflow on Windows. Tags: LPE, Windows Defender, VSS, SAM-hive-leak, RPC, local-user.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>VSS</category><category>SAM-hive-leak</category><category>RPC</category><category>local-user</category></item><item><title>Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46300. Status: Weaponized. Affects: Linux kernel (XFRM ESP-in-TCP subsystem). Tags: LPE, privilege-escalation, kernel, XFRM, ESP-in-TCP, page-cache, write-primitive, unprivileged.</description><category>binary</category><category>High</category><category>LPE</category><category>privilege-escalation</category><category>kernel</category><category>XFRM</category><category>ESP-in-TCP</category><category>page-cache</category><category>write-primitive</category><category>unprivileged</category></item></channel></rss>