<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows-11 — PoC Archive</title><link>https://poc.intelseclab.com/tags/windows-11/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 28 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/windows-11/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-45586. Status: PoC. Affects: Windows Collaborative Translation Framework (CTFMON service). Tags: LPE, EoP, Windows, CTFMON, section-object, object-directory, link-following, zero-day, CTF-challenge, Windows-11, Windows-2022, Windows-2026, incomplete-poc.</description><category>binary</category><category>High</category><category>LPE</category><category>EoP</category><category>Windows</category><category>CTFMON</category><category>section-object</category><category>object-directory</category><category>link-following</category><category>zero-day</category><category>CTF-challenge</category><category>Windows-11</category><category>Windows-2022</category><category>Windows-2026</category><category>incomplete-poc</category></item><item><title>YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)</title><link>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</link><pubDate>Fri, 26 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-06-26_yellowkey-bitlocker-bypass/</guid><description>Medium severity (CVSS 6.1) — misc · CVE-2026-45585. Status: Researched. Affects: Windows BitLocker / WinRE (autofstx.exe). Tags: BitLocker, bypass, physical-access, WinRE, TPM, autofstx, NTFS-transactions, FsTx, Windows-11, Windows-Server-2022, zero-day, full-disk-access.</description><category>misc</category><category>Medium</category><category>BitLocker</category><category>bypass</category><category>physical-access</category><category>WinRE</category><category>TPM</category><category>autofstx</category><category>NTFS-transactions</category><category>FsTx</category><category>Windows-11</category><category>Windows-Server-2022</category><category>zero-day</category><category>full-disk-access</category></item><item><title>RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-10_rogueplanet-defender-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-50656. Status: Weaponized. Affects: Microsoft Windows Defender / Windows Error Reporting Task Scheduler. Tags: LPE, Windows Defender, race-condition, TOCTOU, ISO-mount, VirtualDisk, Task-Scheduler, WER, EICAR, SYSTEM-shell, Windows-10, Windows-11, local.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows Defender</category><category>race-condition</category><category>TOCTOU</category><category>ISO-mount</category><category>VirtualDisk</category><category>Task-Scheduler</category><category>WER</category><category>EICAR</category><category>SYSTEM-shell</category><category>Windows-10</category><category>Windows-11</category><category>local</category></item><item><title>Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</guid><description>High severity (CVSS 7) — binary · CVE-2025-62215. Status: Weaponized. Affects: Windows Kernel (ntoskrnl.exe / kernel resource synchronization). Tags: EoP, Windows kernel, race condition, double-free, heap corruption, 0day, SYSTEM, Windows 10, Windows 11.</description><category>binary</category><category>High</category><category>EoP</category><category>Windows kernel</category><category>race condition</category><category>double-free</category><category>heap corruption</category><category>0day</category><category>SYSTEM</category><category>Windows 10</category><category>Windows 11</category></item></channel></rss>