Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1231CVE-2022-30216 - Authentication coercion of the Windows “Server” service Off-by-one Error Authentication coercion Microsoft Ben Barnea (@nachoskrnl) Bug Bounty2022-08-132023-06-13
1218CVE-2022-30211: Windows L2TP VPN Memory Leak and Use after Free Vulnerability Memory corruption RCE Microsoft Alex Nichols (@i4mchr00t) Bug Bounty2022-08-152023-06-13
1187Break Me Out Of Sandbox In Old Pipe - CVE-2022-22715 Windows Dirty Pipe Local Privilege Escalation Microsoft k0shl (@KeyZ3r0) Bug Bounty2022-08-232023-06-13
1175SSD Advisory – VhdmpiValidateVirtualDiskSurface LPE Local Privilege Escalation Windows Sana Oshika (@bigshika) Bug Bounty2022-08-262023-06-13
1127CVE-2022-34715: More Microsoft Windows NFS V4 Remote Code Execution RCE Memory corruption Microsoft Quintin Crist Bug Bounty2022-09-062023-06-13
1064Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286) Local Privilege Escalation Windows Driver hacking Seagate x86matthew (@x86matthew) Bug Bounty2022-09-202023-06-13
1047Skype for Business Audit Part 1 - SKYPErsistence Local Privilege Escalation Windows Security code review Microsoft Florian Hauser (@frycos) Bug Bounty2022-09-222023-06-13
1038Microsoft Windows Shift F10 Bypass and Autopilot privilge escalation Local privilege escalation Microsoft Matek Kamilló (@k4m1ll0) Bug Bounty2022-09-242023-06-13
1031New Attack Paths? AS Requested Service Tickets Local Privilege Escalation Windows Kerberos Active Directory Microsoft Charlie Clark (@exploitph) Bug Bounty2022-09-252023-06-13
976Cold Hard Cache — Bypassing RPC Interface Security with Cache Abuse Privilege escalation Windows Microsoft - Bug Bounty2022-10-112023-06-13
911The Logging Dead: Two Event Log Vulnerabilities Haunting Windows DoS Microsoft Dolev Taler Bug Bounty2022-10-252023-06-13
898RC4 Is Still Considered Harmful Kerberos MiTM Local Privilege Escalation Downgrade attack Microsoft (Windows) James Forshaw (@tiraniddo) Bug Bounty2022-10-272023-06-13
893Abusing Windows’ tokens to compromise Active Directory without touching LSASS Local Privilege Escalation Windows Active Directory Privilege Escalation NA Aurélien Chalot (@Defte_) Bug Bounty2022-10-272023-06-13
889Technical Analysis of Windows CLFS Zero-Day Vulnerability CVE-2022-37969 - Part 1: Root Cause Analysis Local Privilege Escalation Windows Microsoft Zscaler Threatlabz (@Threatlabz) Bug Bounty2022-10-282023-06-13
856Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049) Local Privilege Escalation Windows Microsoft Kuba Gretzky (@mrgretzky) Bug Bounty2022-11-082023-06-13
842Windows Kernel: Exploit CVE-2022-35803 in Common Log File System Windows Local Privilege Escalation Type confusion Microsoft luckyu (@uuulucky) Bug Bounty2022-11-112023-06-13
839Every Signature is Broken: On the Insecurity of Microsoft Office’s OOXML Signatures Signature bypass Signature forgery Cryptographic issues Windows Microsoft Simon Rohlmann Bug Bounty2022-11-112023-06-13
824Relaying to AD Certificate Services over RPC Active Directory ADCS Windows NA Sylvain Heiniger (@sploutchy) Bug Bounty2022-11-162023-06-13
823Control Your Types Or Get Pwned: Remote Code Execution In Exchange Powershell Backend RCE Windows Checkmk Piotr Bazydło (@chudyPB) Bug Bounty2022-11-162023-06-13
748Bypassing The Client Side Encryption To Read Internal Windows Server Files Client-side encryption bypass LFI Security code review NA Abhishek Morla (@abhishekmorla) Bug Bounty2022-12-012023-06-13
738SysmonEoP Local Privilege Escalation Windows Microsoft Filip Dragovic (@filip_dragovic) Bug Bounty2022-12-032023-06-13
713Public Report – VPN by Google One Security Assessment Android iOS DoS Windows MacoS Local Privilege Escalation Google Daniel Romero (@daniel_rome) Bug Bounty2022-12-092023-06-13
694You’ve Crossed the Line — Disturbing a Host’s Rest Windows MS-RPC DoS Microsoft Ben Barnea (@nachoskrnl) Bug Bounty2022-12-142023-06-13
559Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP” Kernel hacking Windows RCE Memory corruption Buffer Overflow Microsoft (Windows) Valentina Palmiotti (@chompie1337) Bug Bounty2023-01-202023-06-13
552Activation Context Cache Poisoning: Exploiting CSRSS For Privilege Escalation Local Privilege Escalation Windows Microsoft Simon Zuckerbraun Bug Bounty2023-01-232023-06-13