<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>TOCTOU — PoC Archive</title><link>https://poc.intelseclab.com/tags/toctou/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/toctou/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-42978. Status: PoC. Affects: Windows Push Notifications service (WpnService, wpncore.dll). Tags: windows, kernel, wpnservice, use-after-free, race-condition, toctou, privilege-escalation, etw, sysmon, patch-diffing.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>wpnservice</category><category>use-after-free</category><category>race-condition</category><category>toctou</category><category>privilege-escalation</category><category>etw</category><category>sysmon</category><category>patch-diffing</category></item><item><title>PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41651-packagekit-toctou-lpe/</guid><description>High severity — binary · CVE-2026-41651. Status: PoC. Affects: PackageKit daemon (packagekitd). Tags: linux, packagekit, toctou, race-condition, lpe, polkit, privilege-escalation, dbus.</description><category>binary</category><category>High</category><category>linux</category><category>packagekit</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>polkit</category><category>privilege-escalation</category><category>dbus</category></item><item><title>Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-30332-balena-etcher-toctou/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-30332-balena-etcher-toctou/</guid><description>High severity — binary · CVE-2026-30332. Status: Weaponized. Affects: Balena Etcher for Windows. Tags: toctou, windows, uac, privilege-escalation, balena-etcher, race-condition, temp-file.</description><category>binary</category><category>High</category><category>toctou</category><category>windows</category><category>uac</category><category>privilege-escalation</category><category>balena-etcher</category><category>race-condition</category><category>temp-file</category></item><item><title>ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</guid><description>Medium severity — binary · CVE-2026-1880. Status: PoC. Affects: ASUS DriverHub (driver update utility). Tags: windows, toctou, race-condition, lpe, driverhub, asus, local-privilege-escalation, shellexecute.</description><category>binary</category><category>Medium</category><category>windows</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>driverhub</category><category>asus</category><category>local-privilege-escalation</category><category>shellexecute</category></item><item><title>Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</guid><description>High severity — cloud · CVE-2026-7791. Status: PoC. Affects: Amazon WorkSpaces — Skylight Workspace Config Service. Tags: aws, amazon-workspaces, skylight, toctou, privilege-escalation, arbitrary-file-write, windows, directory-junction.</description><category>cloud</category><category>High</category><category>aws</category><category>amazon-workspaces</category><category>skylight</category><category>toctou</category><category>privilege-escalation</category><category>arbitrary-file-write</category><category>windows</category><category>directory-junction</category></item><item><title>AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-22807-vllm-trust-remote-code-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-22807-vllm-trust-remote-code-bypass/</guid><description>High severity — misc · CVE-2026-22807. Status: PoC. Affects: AI inference/model-loading frameworks that resolve custom model classes via auto_map before validating trust_remote_code (pattern seen in vLLM/Transformers-style loaders). Tags: vllm, huggingface, trust-remote-code, toctou, model-loading, supply-chain, python, code-execution.</description><category>misc</category><category>High</category><category>vllm</category><category>huggingface</category><category>trust-remote-code</category><category>toctou</category><category>model-loading</category><category>supply-chain</category><category>python</category><category>code-execution</category></item><item><title>Docker cp Copy-Out Destination Escape via Symlink Race</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-03_docker-cp-copyout-destination-escape/</guid><description>Medium severity — cloud · None assigned as of 2026-07-03. Status: PoC. Affects: Docker Engine / CLI. Tags: docker, container-escape, toctou, symlink-race, docker-cp, path-traversal, archive-extraction, host-file-write.</description><category>cloud</category><category>Medium</category><category>docker</category><category>container-escape</category><category>toctou</category><category>symlink-race</category><category>docker-cp</category><category>path-traversal</category><category>archive-extraction</category><category>host-file-write</category></item><item><title>CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-26_cve-2026-50656-rogueplanet-checker/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-26_cve-2026-50656-rogueplanet-checker/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Researched. Affects: Microsoft Malware Protection Engine (mpengine.dll, MsMpEng.exe). Tags: LPE, Windows Defender, TOCTOU, symlink, reparse-point, junction, CWE-59, checker, detection, non-destructive, MsMpEng.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>TOCTOU</category><category>symlink</category><category>reparse-point</category><category>junction</category><category>CWE-59</category><category>checker</category><category>detection</category><category>non-destructive</category><category>MsMpEng</category></item><item><title>RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Weaponized. Affects: Microsoft Windows Defender / Windows Error Reporting Task Scheduler. Tags: LPE, Windows Defender, race-condition, TOCTOU, ISO-mount, VirtualDisk, Task-Scheduler, WER, EICAR, SYSTEM-shell, Windows-10, Windows-11, local.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>race-condition</category><category>TOCTOU</category><category>ISO-mount</category><category>VirtualDisk</category><category>Task-Scheduler</category><category>WER</category><category>EICAR</category><category>SYSTEM-shell</category><category>Windows-10</category><category>Windows-11</category><category>local</category></item><item><title>FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition</title><link>https://poc.intelseclab.com/pocs/web/2026-06-08_firefox-focus-ios-uxss-redirect-scheme-race-condition/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-08_firefox-focus-ios-uxss-redirect-scheme-race-condition/</guid><description>Critical severity (CVSS 9.3) — web. Status: Unpatched. Affects: Firefox Focus for iOS. Tags: UXSS, XSS, race-condition, TOCTOU, redirect-validation, javascript-scheme, iOS, Firefox Focus.</description><category>web</category><category>Critical</category><category>UXSS</category><category>XSS</category><category>race-condition</category><category>TOCTOU</category><category>redirect-validation</category><category>javascript-scheme</category><category>iOS</category><category>Firefox Focus</category></item><item><title>RedSun Privileged File Write (CVE-2026-33825)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_redsun-privileged-file-write/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_redsun-privileged-file-write/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-33825. Status: Weaponized. Affects: Microsoft Defender Antivirus (real-time protection) on Windows with Cloud Files APIs. Tags: LPE, privileged-file-write, Windows Defender, Cloud Files API, TOCTOU, file-reparse-point.</description><category>binary</category><category>High</category><category>LPE</category><category>privileged-file-write</category><category>Windows Defender</category><category>Cloud Files API</category><category>TOCTOU</category><category>file-reparse-point</category></item></channel></rss>