PoC Archive PoC Archive

tag

Microsoft

  • CVE-2026-47301 network CRITICAL 9.8

    Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)

    CVE-2026-47301 is a remote code execution vulnerability in Microsoft Configuration Manager (SCCM) that chains four weaknesses: broken access control on the AdminService UploadExtensionInChunks endpoint (any domain user, no RBAC check), CAB extraction…

    Unverified 2026-08-15
  • CVE-2026-27912 network HIGH 8

    Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)

    CVE-2026-27912, nicknamed ResetNightmare by Semperis, is a validation flaw in the Kerberos Change Password protocol that allows an attacker to reset the password of any user or computer account in Active Directory — including Domain Admins, the krbtgt…

    Unverified 2026-08-11
  • Bypass of CVE-2026-50656 binary HIGH 7.8 EPSS 11%

    Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks

    ShieldBreak is a 0-day local privilege escalation exploit that bypasses the patch for CVE-2026-50656 (RoguePlanet), achieving SYSTEM-level code execution from an unprivileged user on fully patched Windows 11 and Server 2025 systems. The exploit was released…

    Unpatched 2026-08-11
  • CVE-2026-25177 network HIGH 8.8

    Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)

    CVE-2026-25177 is a privilege escalation vulnerability in Active Directory Domain Services caused by improper restriction of Unicode characters in Service Principal Names (SPNs). An authenticated user with write-SPN permissions can inject Unicode zero-width…

    Patched 2026-08-11
  • CVE-2026-50522 web CRITICAL 9.8 KEV EPSS 77%

    Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)

    SharePoint's WS-Federation passive sign-in endpoint (/trust/default.aspx) accepts a wresult parameter containing a WS-Trust RequestSecurityTokenResponse that can carry a SecurityContextToken with an embedded Cookie value. Windows Identity Foundation's…

    Patched 2026-07-27