<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Unprivileged — PoC Archive</title><link>https://poc.intelseclab.com/tags/unprivileged/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/unprivileged/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2636-clfs-sys-bsod/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2636-clfs-sys-bsod/</guid><description>Medium severity — binary · CVE-2026-2636. Status: PoC. Affects: Windows Common Log File System driver (CLFS.sys, version 10.0.22621.5037 used as reference). Tags: clfs, windows-kernel-driver, bsod, denial-of-service, cwe-159, irp, kebugcheckex, unprivileged.</description><category>binary</category><category>Medium</category><category>clfs</category><category>windows-kernel-driver</category><category>bsod</category><category>denial-of-service</category><category>cwe-159</category><category>irp</category><category>kebugcheckex</category><category>unprivileged</category></item><item><title>Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-23416-linux-kernel-mseal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-23416-linux-kernel-mseal/</guid><description>Medium severity — binary · CVE-2026-23416. Status: PoC. Affects: Linux kernel, mm/mseal.c / mm/vma.c (mseal_apply() / vma_merge_existing_range()). Tags: linux-kernel, mseal, mm-subsystem, vma, logic-error, unprivileged, security-feature-bypass, memfd.</description><category>binary</category><category>Medium</category><category>linux-kernel</category><category>mseal</category><category>mm-subsystem</category><category>vma</category><category>logic-error</category><category>unprivileged</category><category>security-feature-bypass</category><category>memfd</category></item><item><title>Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31694-fuse-readdir-cache-oob/</guid><description>High severity — binary · CVE-2026-31694. Status: Weaponized. Affects: Linux kernel — fs/fuse/readdir.c (fuse_add_dirent_to_cache()). Tags: linux-kernel, fuse, oob-write, page-cache, lpe, groom, unprivileged, qemu-kvm.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>fuse</category><category>oob-write</category><category>page-cache</category><category>lpe</category><category>groom</category><category>unprivileged</category><category>qemu-kvm</category></item><item><title>DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-31635-dirtydecrypt-go-rxgk-lpe/</guid><description>High severity — binary · CVE-2026-31635. Status: Weaponized. Affects: Linux kernel — net/rxrpc/rxgk_common.h (rxgk_decrypt_skb()). Tags: linux-kernel, lpe, rxrpc, rxgk, page-cache, dirty-pipe-variant, splice, golang, unprivileged.</description><category>binary</category><category>High</category><category>linux-kernel</category><category>lpe</category><category>rxrpc</category><category>rxgk</category><category>page-cache</category><category>dirty-pipe-variant</category><category>splice</category><category>golang</category><category>unprivileged</category></item><item><title>DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-18_dirtydecrypt/</guid><description>High severity — binary · N/A (reported as duplicate by kernel maintainers; patched on mainline). Status: Weaponized. Affects: Linux kernel — net/rxrpc (rxgk_decrypt_skb). Tags: LPE, Linux kernel, page-cache, rxgk, RxRPC, COW, write-primitive, unprivileged, Dirty-Pipe-variant, splice, MSG_SPLICE_PAGES.</description><category>binary</category><category>High</category><category>LPE</category><category>Linux kernel</category><category>page-cache</category><category>rxgk</category><category>RxRPC</category><category>COW</category><category>write-primitive</category><category>unprivileged</category><category>Dirty-Pipe-variant</category><category>splice</category><category>MSG_SPLICE_PAGES</category></item><item><title>Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-14_linux-xfrm-fragnesia-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-46300. Status: Weaponized. Affects: Linux kernel (XFRM ESP-in-TCP subsystem). Tags: LPE, privilege-escalation, kernel, XFRM, ESP-in-TCP, page-cache, write-primitive, unprivileged.</description><category>binary</category><category>High</category><category>LPE</category><category>privilege-escalation</category><category>kernel</category><category>XFRM</category><category>ESP-in-TCP</category><category>page-cache</category><category>write-primitive</category><category>unprivileged</category></item></channel></rss>