<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows — PoC Archive</title><link>https://poc.intelseclab.com/tags/windows/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/windows/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-16_cve-2026-21508-windows-mediaplayer-dll-hijack-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-21508. Status: Patched. Affects: Microsoft Windows Media Player / WUDFHost.exe. Tags: windows, dll-hijack, lpe, privilege-escalation, media-player, wudfhost, session0, com-hijack, CVE-2026-21508.</description><category>binary</category><category>High</category><category>windows</category><category>dll-hijack</category><category>lpe</category><category>privilege-escalation</category><category>media-player</category><category>wudfhost</category><category>session0</category><category>com-hijack</category><category>CVE-2026-21508</category></item><item><title>Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-47301. Status: Patched. Affects: Microsoft Configuration Manager (SCCM / ConfigMgr), AdminService REST API. Tags: windows, sccm, configmgr, rce, cab, path-traversal, dll-hijacking, dll-proxy, arbitrary-file-write, system, microsoft, CVE-2026-47301.</description><category>network</category><category>Critical</category><category>windows</category><category>sccm</category><category>configmgr</category><category>rce</category><category>cab</category><category>path-traversal</category><category>dll-hijacking</category><category>dll-proxy</category><category>arbitrary-file-write</category><category>system</category><category>microsoft</category><category>CVE-2026-47301</category></item><item><title>Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-27912-resetnightmare-kerberos-changepw-password-reset/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-27912-resetnightmare-kerberos-changepw-password-reset/</guid><description>High severity (CVSS 8) — network · CVE-2026-27912. Status: Patched. Affects: Microsoft Windows Kerberos Key Distribution Center (KDC), Change Password protocol (kadmin/changepw). Tags: windows, kerberos, active-directory, privilege-escalation, password-reset, domain-controller, upn, rubeus, changepw, krbtgt, CWE-285, microsoft, CVE-2026-27912.</description><category>network</category><category>High</category><category>windows</category><category>kerberos</category><category>active-directory</category><category>privilege-escalation</category><category>password-reset</category><category>domain-controller</category><category>upn</category><category>rubeus</category><category>changepw</category><category>krbtgt</category><category>CWE-285</category><category>microsoft</category><category>CVE-2026-27912</category></item><item><title>Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-11_shieldbreak-defender-rogueplanet-patch-bypass/</guid><description>High severity (CVSS 7.8) — binary · Bypass of CVE-2026-50656 (RoguePlanet); no CVE assigned to ShieldBreak as of 2026-08-11. Status: Unpatched. Affects: Microsoft Windows Defender (Antimalware Service Executable / MsMpEng.exe), threat remediation subsystem. Tags: windows, windows-defender, lpe, privilege-escalation, 0day, patch-bypass, cloud-files, cfapi, object-manager, symlink, wer, dll-sideload, CWE-59, CWE-426, microsoft, rogueplanet, shieldbreak.</description><category>binary</category><category>High</category><category>windows</category><category>windows-defender</category><category>lpe</category><category>privilege-escalation</category><category>0day</category><category>patch-bypass</category><category>cloud-files</category><category>cfapi</category><category>object-manager</category><category>symlink</category><category>wer</category><category>dll-sideload</category><category>CWE-59</category><category>CWE-426</category><category>microsoft</category><category>rogueplanet</category><category>shieldbreak</category></item><item><title>Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</guid><description>High severity (CVSS 8.8) — network · CVE-2026-25177. Status: Patched. Affects: Microsoft Active Directory Domain Services, Service Principal Name (SPN) validation. Tags: windows, active-directory, kerberos, spn, unicode, homoglyph, privilege-escalation, detection, scanner, ldap, CWE-641, microsoft, CVE-2026-25177.</description><category>network</category><category>High</category><category>windows</category><category>active-directory</category><category>kerberos</category><category>spn</category><category>unicode</category><category>homoglyph</category><category>privilege-escalation</category><category>detection</category><category>scanner</category><category>ldap</category><category>CWE-641</category><category>microsoft</category><category>CVE-2026-25177</category></item><item><title>Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-01_notcve-2026-0010-barrier-daemon-lpe/</guid><description>High severity — binary · NotCVE-2026-0010 (disputed CVE assignment — author contests the identifier). Status: Unpatched — Barrier is unmaintained with no vendor fix; patched successor Deskflow covers the same issue via CVE-2026-41477 / GHSA-6rx5-g478-775c. Affects: Barrier (debauchee), Windows service daemon barrierd.exe. Tags: barrier, barrierd, windows, ipc, tcp-24801, unauthenticated, lpe, privilege-escalation, system, cwe-306, local.</description><category>binary</category><category>High</category><category>barrier</category><category>barrierd</category><category>windows</category><category>ipc</category><category>tcp-24801</category><category>unauthenticated</category><category>lpe</category><category>privilege-escalation</category><category>system</category><category>cwe-306</category><category>local</category></item><item><title>Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_cve-2026-49176-windows-walletservice-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-49176. Status: Weaponized — SYSTEM shell confirmed against a real, vulnerable Windows 11 build. Affects: Windows WalletService (Windows.ApplicationModel.Wallet WinRT API, backed by an ESE/Jet Blue database under the caller's Documents\Wallet folder). Tags: windows, walletservice, lpe, privilege-escalation, ese, extensible-storage-engine, known-folder-redirection, persisted-callback, local.</description><category>binary</category><category>High</category><category>windows</category><category>walletservice</category><category>lpe</category><category>privilege-escalation</category><category>ese</category><category>extensible-storage-engine</category><category>known-folder-redirection</category><category>persisted-callback</category><category>local</category></item><item><title>Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</guid><description>High severity (CVSS 8.4) — network · CVE-2026-54992. Status: PoC (crash/DoS confirmed, no RCE demonstrated). Affects: Windows Message Queuing (MSMQ) — Queue Manager (mqqm.dll, hosted in mqsvc.exe), reached via the MS-MQRR (RemoteRead) RPC interface. Tags: windows, msmq, message-queuing, heap-overflow, integer-overflow, rpc, dos, crash.</description><category>network</category><category>High</category><category>windows</category><category>msmq</category><category>message-queuing</category><category>heap-overflow</category><category>integer-overflow</category><category>rpc</category><category>dos</category><category>crash</category></item><item><title>GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-27_greatxml-winre-bitlocker-bypass/</guid><description>High severity — binary · N/A (no CVE assigned, no Microsoft advisory as of 2026-07-27). Status: Unpatched. Affects: Windows Recovery Environment (WinRE) — Microsoft Defender Offline Scan launch path (ReAgent.xml scheduled operation). Tags: windows, bitlocker, winre, defender, offline-scan, trust-boundary-bypass, zero-day, unpatched, physical-access, local.</description><category>binary</category><category>High</category><category>windows</category><category>bitlocker</category><category>winre</category><category>defender</category><category>offline-scan</category><category>trust-boundary-bypass</category><category>zero-day</category><category>unpatched</category><category>physical-access</category><category>local</category></item><item><title>AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54121-certighost-adcs-dc-impersonation/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54121-certighost-adcs-dc-impersonation/</guid><description>High severity (CVSS 8.8) — network · CVE-2026-54121. Status: Weaponized. Affects: Microsoft Active Directory Certificate Services (AD CS) Enterprise CA, in environments where AD FS / certificate enrollment resolves DC identity via "chase" (cdc/rmd) request attributes. Tags: active-directory, adcs, certificate-services, dcsync, pkinit, kerberos, privilege-escalation, domain-controller-impersonation, windows.</description><category>network</category><category>High</category><category>active-directory</category><category>adcs</category><category>certificate-services</category><category>dcsync</category><category>pkinit</category><category>kerberos</category><category>privilege-escalation</category><category>domain-controller-impersonation</category><category>windows</category></item><item><title>LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-19_legacyhive-user-profile-service-hive-load-lpe/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-19_legacyhive-user-profile-service-hive-load-lpe/</guid><description>High severity — binary. Status: Weaponized. Affects: Microsoft Windows user profile service / registry hive loading path. Tags: windows, lpe, user-profile-service, registry-hive, usrclass.dat, oplock, symbolic-link.</description><category>binary</category><category>High</category><category>windows</category><category>lpe</category><category>user-profile-service</category><category>registry-hive</category><category>usrclass.dat</category><category>oplock</category><category>symbolic-link</category></item><item><title>React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-11953. Status: Weaponized. Affects: @react-native-community/cli / @react-native-community/cli-server-api (Metro Development Server, openURLMiddleware). Tags: react-native, metro, dev-server, cli-server-api, open-url, command-injection, cwe-78, unauthenticated, node.js, python, windows, cross-platform.</description><category>network</category><category>Critical</category><category>react-native</category><category>metro</category><category>dev-server</category><category>cli-server-api</category><category>open-url</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>node.js</category><category>python</category><category>windows</category><category>cross-platform</category></item><item><title>XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3609-xigncode3-lsass-credential-dump/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3609-xigncode3-lsass-credential-dump/</guid><description>High severity — binary · CVE-2026-3609. Status: Weaponized. Affects: Wellbia XIGNCODE3 anti-cheat driver (xhunter1.sys). Tags: lsass, credential-dumping, anti-cheat, kernel-driver, ppl-bypass, xigncode3, windows, byovd.</description><category>binary</category><category>High</category><category>lsass</category><category>credential-dumping</category><category>anti-cheat</category><category>kernel-driver</category><category>ppl-bypass</category><category>xigncode3</category><category>windows</category><category>byovd</category></item><item><title>Windows ShellLink (.lnk) Remote Code Execution — CVE-2026-21510 LNK-Stomping Generator</title><link>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21510-lnk-stomping-generator/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/social-engineering/2026-07-05_cve-2026-21510-lnk-stomping-generator/</guid><description>High severity — social-engineering · CVE-2026-21510. Status: Weaponized. Affects: Windows Shell Link (.lnk) parsing (MS-SHLLINK). Tags: lnk-stomping, shelllink, cve-2026-21510, windows, initial-access, phishing, anti-forensics, red-team.</description><category>social-engineering</category><category>High</category><category>lnk-stomping</category><category>shelllink</category><category>cve-2026-21510</category><category>windows</category><category>initial-access</category><category>phishing</category><category>anti-forensics</category><category>red-team</category></item><item><title>Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32202-lnk-idcontrolw-builder/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32202-lnk-idcontrolw-builder/</guid><description>High severity — binary · CVE-2026-32202 (related: CVE-2026-21510). Status: PoC. Affects: Windows Shell (shell32.dll) / Windows Explorer. Tags: lnk, shell32, windows, apt28, smb-coercion, zero-click, reverse-engineering, control-panel.</description><category>binary</category><category>High</category><category>lnk</category><category>shell32</category><category>windows</category><category>apt28</category><category>smb-coercion</category><category>zero-click</category><category>reverse-engineering</category><category>control-panel</category></item><item><title>Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-42978-wpn-uaf-race/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-42978. Status: PoC. Affects: Windows Push Notifications service (WpnService, wpncore.dll). Tags: windows, kernel, wpnservice, use-after-free, race-condition, toctou, privilege-escalation, etw, sysmon, patch-diffing.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>wpnservice</category><category>use-after-free</category><category>race-condition</category><category>toctou</category><category>privilege-escalation</category><category>etw</category><category>sysmon</category><category>patch-diffing</category></item><item><title>Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-40369-windows-kernel-lpe/</guid><description>High severity — binary · CVE-2026-40369. Status: PoC. Affects: Windows kernel (ntoskrnl.exe). Tags: windows, kernel, lpe, privilege-escalation, token-stealing, sedebugprivilege, ntoskrnl, local.</description><category>binary</category><category>High</category><category>windows</category><category>kernel</category><category>lpe</category><category>privilege-escalation</category><category>token-stealing</category><category>sedebugprivilege</category><category>ntoskrnl</category><category>local</category></item><item><title>Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</guid><description>High severity — binary · CVE-2026-49160. Status: PoC. Affects: Windows HTTP.sys kernel-mode driver (Windows 10 build 26100 confirmed in crash logs). Tags: windows, http.sys, kernel, http2, dos, bsod, memory-corruption, integer-overflow.</description><category>binary</category><category>High</category><category>windows</category><category>http.sys</category><category>kernel</category><category>http2</category><category>dos</category><category>bsod</category><category>memory-corruption</category><category>integer-overflow</category></item><item><title>Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20817-windows-wer-alpc-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20817-windows-wer-alpc-lpe/</guid><description>High severity — binary · CVE-2026-20817. Status: PoC. Affects: Windows Error Reporting Service (WerSvc). Tags: windows, wersvc, alpc, lpe, privilege-escalation, ntdll, system32, native-cpp.</description><category>binary</category><category>High</category><category>windows</category><category>wersvc</category><category>alpc</category><category>lpe</category><category>privilege-escalation</category><category>ntdll</category><category>system32</category><category>native-cpp</category></item><item><title>Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</guid><description>Medium severity — binary · CVE-2026-3008. Status: PoC. Affects: Notepad++ 8.9.3. Tags: notepad++, format-string, wsprintfw, dos, information-disclosure, localization, windows.</description><category>binary</category><category>Medium</category><category>notepad++</category><category>format-string</category><category>wsprintfw</category><category>dos</category><category>information-disclosure</category><category>localization</category><category>windows</category></item><item><title>MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36981-minitool-kernel-driver-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36981-minitool-kernel-driver-lpe/</guid><description>High severity — binary · CVE-2026-36981. Status: PoC. Affects: MiniTool pwdrvio.sys kernel driver. Tags: minitool, kernel-driver, write-what-where, lpe, arbitrary-kernel-write, windows.</description><category>binary</category><category>High</category><category>minitool</category><category>kernel-driver</category><category>write-what-where</category><category>lpe</category><category>arbitrary-kernel-write</category><category>windows</category></item><item><title>MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36980-minitool-kernel-driver-bsod-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36980-minitool-kernel-driver-bsod-dos/</guid><description>Medium severity — binary · CVE-2026-36980. Status: PoC. Affects: MiniTool pwdrvio.sys kernel driver. Tags: minitool, kernel-driver, ioctl, bsod, dos, pool-corruption, windows.</description><category>binary</category><category>Medium</category><category>minitool</category><category>kernel-driver</category><category>ioctl</category><category>bsod</category><category>dos</category><category>pool-corruption</category><category>windows</category></item><item><title>Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41091-defender-link-following-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-41091-defender-link-following-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-41091. Status: Weaponized. Affects: Microsoft Defender / Microsoft Malware Protection Engine. Tags: windows, microsoft-defender, link-following, cwe-59, cloud-files-api, ntfs-junction, oplock, privilege-escalation, lpe.</description><category>binary</category><category>High</category><category>windows</category><category>microsoft-defender</category><category>link-following</category><category>cwe-59</category><category>cloud-files-api</category><category>ntfs-junction</category><category>oplock</category><category>privilege-escalation</category><category>lpe</category></item><item><title>Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0827-lenovo-lde-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0827-lenovo-lde-file-write/</guid><description>High severity — binary · CVE-2026-0827 (Lenovo advisory LEN-210693). Status: PoC. Affects: Lenovo LDE (LdeApi.Server.exe). Tags: lenovo, lde, windows, junction, ntfs-symlink, privilege-escalation, unimpersonated-write, local-privesc.</description><category>binary</category><category>High</category><category>lenovo</category><category>lde</category><category>windows</category><category>junction</category><category>ntfs-symlink</category><category>privilege-escalation</category><category>unimpersonated-write</category><category>local-privesc</category></item><item><title>KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0828-killchain-driver-ioctl/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0828-killchain-driver-ioctl/</guid><description>High severity — binary · CVE-2026-0828. Status: Weaponized. Affects: ProcessMonitorDriver.sys (vulnerable third-party kernel driver). Tags: byovd, kernel-driver, ioctl, process-termination, edr-killer, windows, privilege-escalation, defender-bypass.</description><category>binary</category><category>High</category><category>byovd</category><category>kernel-driver</category><category>ioctl</category><category>process-termination</category><category>edr-killer</category><category>windows</category><category>privilege-escalation</category><category>defender-bypass</category></item><item><title>Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0776-discord-search-path/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0776-discord-search-path/</guid><description>High severity (CVSS 7.3) — binary · CVE-2026-0776 (ZDI-CAN-27057, credit: Trend Micro Zero Day Initiative). Status: PoC. Affects: Discord Desktop Client (Windows). Tags: discord, cwe-427, search-path-hijack, node-modules, local-code-execution, windows, electron.</description><category>binary</category><category>High</category><category>discord</category><category>cwe-427</category><category>search-path-hijack</category><category>node-modules</category><category>local-code-execution</category><category>windows</category><category>electron</category></item><item><title>Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-30332-balena-etcher-toctou/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-30332-balena-etcher-toctou/</guid><description>High severity — binary · CVE-2026-30332. Status: Weaponized. Affects: Balena Etcher for Windows. Tags: toctou, windows, uac, privilege-escalation, balena-etcher, race-condition, temp-file.</description><category>binary</category><category>High</category><category>toctou</category><category>windows</category><category>uac</category><category>privilege-escalation</category><category>balena-etcher</category><category>race-condition</category><category>temp-file</category></item><item><title>ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-1880-asus-driverhub-toctou-lpe/</guid><description>Medium severity — binary · CVE-2026-1880. Status: PoC. Affects: ASUS DriverHub (driver update utility). Tags: windows, toctou, race-condition, lpe, driverhub, asus, local-privilege-escalation, shellexecute.</description><category>binary</category><category>Medium</category><category>windows</category><category>toctou</category><category>race-condition</category><category>lpe</category><category>driverhub</category><category>asus</category><category>local-privilege-escalation</category><category>shellexecute</category></item><item><title>Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22444-solr-unc-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22444-solr-unc-rce/</guid><description>Critical severity — web · CVE-2026-22444. Status: Weaponized. Affects: Apache Solr, standalone mode, running on Windows. Tags: apache-solr, rce, unc-path, smb, configset, javascript-script-update-processor, windows, cwe-20.</description><category>web</category><category>Critical</category><category>apache-solr</category><category>rce</category><category>unc-path</category><category>smb</category><category>configset</category><category>javascript-script-update-processor</category><category>windows</category><category>cwe-20</category></item><item><title>Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-7791-aws-workspaces-skylight-lpe/</guid><description>High severity — cloud · CVE-2026-7791. Status: PoC. Affects: Amazon WorkSpaces — Skylight Workspace Config Service. Tags: aws, amazon-workspaces, skylight, toctou, privilege-escalation, arbitrary-file-write, windows, directory-junction.</description><category>cloud</category><category>High</category><category>aws</category><category>amazon-workspaces</category><category>skylight</category><category>toctou</category><category>privilege-escalation</category><category>arbitrary-file-write</category><category>windows</category><category>directory-junction</category></item><item><title>VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_vlc-vp9-reschange-crash/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_vlc-vp9-reschange-crash/</guid><description>Medium severity — binary · None assigned as of 2026-07-03. Status: Incomplete PoC. Affects: VLC media player, bundled FFmpeg VP9 decoder (plugins/codec/libavcodec_plugin.dll). Tags: vlc, ffmpeg, vp9, ivf, heap-overflow, media-parsing, crash, windows, decoder.</description><category>binary</category><category>Medium</category><category>vlc</category><category>ffmpeg</category><category>vp9</category><category>ivf</category><category>heap-overflow</category><category>media-parsing</category><category>crash</category><category>windows</category><category>decoder</category></item><item><title>System Informer phsvc Trusted-Host Confused Deputy LPE</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_systeminformer-phsvc-trusted-host-lpe/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_systeminformer-phsvc-trusted-host-lpe/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: System Informer (Process Hacker successor), phsvc helper process. Tags: windows, system-informer, process-hacker, lpe, confused-deputy, alpc, phsvc, authenticode, local-privilege-escalation.</description><category>binary</category><category>High</category><category>windows</category><category>system-informer</category><category>process-hacker</category><category>lpe</category><category>confused-deputy</category><category>alpc</category><category>phsvc</category><category>authenticode</category><category>local-privilege-escalation</category></item><item><title>OpenVPN Connect Server-Pushed Option Current-User Command Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_openvpn-connect-server-pushed-option-ace/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_openvpn-connect-server-pushed-option-ace/</guid><description>High severity — network · None assigned as of 2026-07-03. Status: PoC. Affects: OpenVPN Connect for Windows. Tags: openvpn, openvpn-connect, malicious-vpn-server, command-execution, script-permission-bypass, pushed-options, windows, client-side.</description><category>network</category><category>High</category><category>openvpn</category><category>openvpn-connect</category><category>malicious-vpn-server</category><category>command-execution</category><category>script-permission-bypass</category><category>pushed-options</category><category>windows</category><category>client-side</category></item><item><title>libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: libssh2, publickey subsystem list parser (src/publickey.c). Tags: libssh2, ssh, publickey-subsystem, heap-overflow, use-after-free, integer-overflow, windows, rce, memory-corruption.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>publickey-subsystem</category><category>heap-overflow</category><category>use-after-free</category><category>integer-overflow</category><category>windows</category><category>rce</category><category>memory-corruption</category></item><item><title>ImageMagick Ghostscript Delegate Search Path Hijack</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_imagemagick-ghostscript-delegate-hijack/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_imagemagick-ghostscript-delegate-hijack/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: ImageMagick (Ghostscript delegate for PDF/PS/EPS conversion) on Windows. Tags: imagemagick, ghostscript, windows, search-path-hijack, dll-planting-adjacent, delegate-execution, code-execution, pdf.</description><category>binary</category><category>High</category><category>imagemagick</category><category>ghostscript</category><category>windows</category><category>search-path-hijack</category><category>dll-planting-adjacent</category><category>delegate-execution</category><category>code-execution</category><category>pdf</category></item><item><title>Flowise Custom MCP Environment Variable Case Bypass</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_flowise-mcp-env-var-case-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_flowise-mcp-env-var-case-bypass/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: Flowise / flowise-components. Tags: flowise, mcp, model-context-protocol, windows, environment-variable, case-insensitivity, node-options, rce.</description><category>web</category><category>High</category><category>flowise</category><category>mcp</category><category>model-context-protocol</category><category>windows</category><category>environment-variable</category><category>case-insensitivity</category><category>node-options</category><category>rce</category></item><item><title>AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_anydesk-printer-pipe-com-impersonation-lpe/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_anydesk-printer-pipe-com-impersonation-lpe/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: AnyDesk for Windows 9.7.6. Tags: anydesk, windows, privilege-escalation, com-impersonation, named-pipe, local-service, lpe, ipc.</description><category>binary</category><category>High</category><category>anydesk</category><category>windows</category><category>privilege-escalation</category><category>com-impersonation</category><category>named-pipe</category><category>local-service</category><category>lpe</category><category>ipc</category></item><item><title>7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-03_7zip-rar5-motw-ads-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-03_7zip-rar5-motw-ads-bypass/</guid><description>High severity — misc · None assigned as of 2026-07-03. Status: PoC. Affects: 7-Zip 26.01 x64 for Windows. Tags: 7-zip, rar5, mark-of-the-web, alternate-data-streams, ntfs, motw-bypass, windows, archive-extraction.</description><category>misc</category><category>High</category><category>7-zip</category><category>rar5</category><category>mark-of-the-web</category><category>alternate-data-streams</category><category>ntfs</category><category>motw-bypass</category><category>windows</category><category>archive-extraction</category></item><item><title>Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-28_cve-2026-45586-ctfmon-greenplasma-lpe/</guid><description>High severity (CVSS 7.8) — binary · CVE-2026-45586. Status: PoC. Affects: Windows Collaborative Translation Framework (CTFMON service). Tags: LPE, EoP, Windows, CTFMON, section-object, object-directory, link-following, zero-day, CTF-challenge, Windows-11, Windows-2022, Windows-2026, incomplete-poc.</description><category>binary</category><category>High</category><category>LPE</category><category>EoP</category><category>Windows</category><category>CTFMON</category><category>section-object</category><category>object-directory</category><category>link-following</category><category>zero-day</category><category>CTF-challenge</category><category>Windows-11</category><category>Windows-2022</category><category>Windows-2026</category><category>incomplete-poc</category></item><item><title>Notepad++ &lt;= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</guid><description>High severity (CVSS 5) — binary · CVE-2026-48770, CVE-2026-48778, CVE-2026-48800. Status: Patched. Affects: Notepad++. Tags: Notepad++, Windows, OOB-read, DoS, command-injection, config.xml, shortcuts.xml, local.</description><category>binary</category><category>High</category><category>Notepad++</category><category>Windows</category><category>OOB-read</category><category>DoS</category><category>command-injection</category><category>config.xml</category><category>shortcuts.xml</category><category>local</category></item><item><title>Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-ntlm-hash-disclosure-cve-2025-24054/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-ntlm-hash-disclosure-cve-2025-24054/</guid><description>Medium severity (CVSS 6.5) — binary · CVE-2025-24054. Status: Patched. Affects: Windows File Explorer (Windows Shell). Tags: NTLM, NTLMv2, hash-disclosure, zero-click, Windows, File-Explorer, UNC, SMB, credential-theft, in-the-wild, state-sponsored.</description><category>binary</category><category>Medium</category><category>NTLM</category><category>NTLMv2</category><category>hash-disclosure</category><category>zero-click</category><category>Windows</category><category>File-Explorer</category><category>UNC</category><category>SMB</category><category>credential-theft</category><category>in-the-wild</category><category>state-sponsored</category></item><item><title>Windows MMC MSC EvilTwin - CVE-2025-26633</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-mmc-eviltwin-cve-2025-26633/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-mmc-eviltwin-cve-2025-26633/</guid><description>High severity — binary · CVE-2025-26633. Status: Patched. Affects: Microsoft Management Console (MMC), Windows. Tags: RCE, Windows, MMC, MSC, ActiveX, EvilTwin, APT, EncryptHub, Water-Gamayun, zero-day, in-the-wild.</description><category>binary</category><category>High</category><category>RCE</category><category>Windows</category><category>MMC</category><category>MSC</category><category>ActiveX</category><category>EvilTwin</category><category>APT</category><category>EncryptHub</category><category>Water-Gamayun</category><category>zero-day</category><category>in-the-wild</category></item><item><title>ToolShell - SharePoint Unauthenticated RCE Chain</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_toolshell-sharepoint-chain/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_toolshell-sharepoint-chain/</guid><description>Critical severity — web · CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706. Status: Weaponized. Affects: Microsoft SharePoint Server. Tags: RCE, SharePoint, unauthenticated, deserialization, auth-bypass, APT27, APT31, ransomware, Windows, IIS.</description><category>web</category><category>Critical</category><category>RCE</category><category>SharePoint</category><category>unauthenticated</category><category>deserialization</category><category>auth-bypass</category><category>APT27</category><category>APT31</category><category>ransomware</category><category>Windows</category><category>IIS</category></item><item><title>Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_cve-2025-21298-outlook-rtf-rce/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_cve-2025-21298-outlook-rtf-rce/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2025-21298. Status: Researched. Affects: Microsoft Windows OLE (ole32.dll) as reached by Outlook/Word RTF parsing. Tags: RCE, zero-click, Outlook, RTF, OLE, ole32, Windows, memory-corruption, unauthenticated.</description><category>binary</category><category>Critical</category><category>RCE</category><category>zero-click</category><category>Outlook</category><category>RTF</category><category>OLE</category><category>ole32</category><category>Windows</category><category>memory-corruption</category><category>unauthenticated</category></item><item><title>Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_adobe-acrobat-prototype-pollution-sandbox-escape/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_adobe-acrobat-prototype-pollution-sandbox-escape/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-34621. Status: Weaponized. Affects: Adobe Acrobat DC / Adobe Acrobat Reader DC / Adobe Acrobat 2024 JavaScript engine sandbox boundary. Tags: prototype-pollution, sandbox-escape, Adobe-Acrobat, Adobe-Reader, PDF, RCE, Windows, macOS, user-interaction.</description><category>binary</category><category>Critical</category><category>prototype-pollution</category><category>sandbox-escape</category><category>Adobe-Acrobat</category><category>Adobe-Reader</category><category>PDF</category><category>RCE</category><category>Windows</category><category>macOS</category><category>user-interaction</category></item><item><title>WinRAR Archive Extraction Path Traversal (CVE-2025-6218)</title><link>https://poc.intelseclab.com/pocs/misc/2026-05-15_winrar-path-traversal-cve-2025-6218/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-05-15_winrar-path-traversal-cve-2025-6218/</guid><description>High severity — misc · CVE-2025-6218. Status: Weaponized. Affects: WinRAR archive extraction workflow. Tags: path-traversal, arbitrary-file-write, startup-folder, WinRAR, Windows, user-interaction.</description><category>misc</category><category>High</category><category>path-traversal</category><category>arbitrary-file-write</category><category>startup-folder</category><category>WinRAR</category><category>Windows</category><category>user-interaction</category></item><item><title>MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_miniplasma-cve-2020-17103/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_miniplasma-cve-2020-17103/</guid><description>High severity (CVSS 7.8) — binary · CVE-2020-17103. Status: Weaponized. Affects: Windows Cloud Files Mini Filter Driver (cldflt.sys) / cldapi.dll. Tags: LPE, Windows, cldflt.sys, Cloud Files API, registry-symlink, race-condition, WER-hijack, SYSTEM-shell, local-user.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows</category><category>cldflt.sys</category><category>Cloud Files API</category><category>registry-symlink</category><category>race-condition</category><category>WER-hijack</category><category>SYSTEM-shell</category><category>local-user</category></item><item><title>HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-15_cve-2021-31166-http-sys-uaf/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-15_cve-2021-31166-http-sys-uaf/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2021-31166. Status: Weaponized. Affects: Microsoft Windows HTTP Protocol Stack (http.sys). Tags: HTTP.sys, use-after-free, RCE, Windows, kernel, unauthenticated.</description><category>network</category><category>Critical</category><category>HTTP.sys</category><category>use-after-free</category><category>RCE</category><category>Windows</category><category>kernel</category><category>unauthenticated</category></item><item><title>CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-15_cve-2024-21338-admin-to-kernel/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-15_cve-2024-21338-admin-to-kernel/</guid><description>High severity (CVSS 7.8) — binary · CVE-2024-21338. Status: Weaponized. Affects: Microsoft Windows AppLocker driver path (\\Device\\AppID). Tags: LPE, Windows, AppLocker, token-impersonation, HVCI, admin-to-kernel, local-user.</description><category>binary</category><category>High</category><category>LPE</category><category>Windows</category><category>AppLocker</category><category>token-impersonation</category><category>HVCI</category><category>admin-to-kernel</category><category>local-user</category></item></channel></rss>