Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1143Azure Synapse: Local Privilege Escalation Vulnerability in Spark Race condition Local Privilege Escalation Cloud Microsoft Tzah Pahima (@TzahPahima) Bug Bounty2022-09-012023-06-13
1133Simple IBM I (AS/400) Hacking Local Privilege Escalation Midrange system Menu security NA pz Bug Bounty2022-09-052023-06-13
1132SSD Advisory – Linux CONFIG_WATCH_QUEUE LPE Memory corruption Race condition Local Privilege Escalation Ubuntu Linux Kernel Organization - Bug Bounty2022-09-052023-06-13
1131Hacking My Helium Crypto Miner Hardcoded credentials Missing authentication RCE Local Privilege Escalation Pycom Md. Asif Hossain (@0x0asif) Bug Bounty2022-09-052023-06-13
1120Quasar: Compromising Electron Apps Local Privilege Escalation Microsoft Taggart (@mttaggart) Bug Bounty2022-09-062023-06-13
1106Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution Arbitrary Code Execution Local Privilege Escalation AVEVA Daan Keuper (@daankeuper) Bug Bounty2022-09-082023-06-13
1064Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286) Local Privilege Escalation Windows Driver hacking Seagate x86matthew (@x86matthew) Bug Bounty2022-09-202023-06-13
1047Skype for Business Audit Part 1 - SKYPErsistence Local Privilege Escalation Windows Security code review Microsoft Florian Hauser (@frycos) Bug Bounty2022-09-222023-06-13
1038Microsoft Windows Shift F10 Bypass and Autopilot privilge escalation Local privilege escalation Microsoft Matek Kamilló (@k4m1ll0) Bug Bounty2022-09-242023-06-13
1031New Attack Paths? AS Requested Service Tickets Local Privilege Escalation Windows Kerberos Active Directory Microsoft Charlie Clark (@exploitph) Bug Bounty2022-09-252023-06-13
1025Another Tale Of IBM I (AS/400) Hacking Local Privilege Escalation Midrange system Menu security NA pz Bug Bounty2022-09-282023-06-13
1024Two RCEs are better than one: write-up of an interesting lateral movement Local Privilege Escalation RCE NA Riccardo Malatesta (@seeu_inspace) Bug Bounty2022-09-282023-06-13
953[CVE-2022-1786] A Journey To The Dawn Use-After-Free Memory corruption Local Privilege Escalation Google (kCTF) Linux Kernel Organization kylebot (@ky1ebot) Bug Bounty2022-10-152023-06-13
901SiriSpy - iOS bug allowed apps to eavesdrop on your conversations with Siri iOS MacOS Bluetooth Local Privilege Escalation TCC bypass Apple Guilherme Rambo (@_inside) Bug Bounty2022-10-262023-06-13
898RC4 Is Still Considered Harmful Kerberos MiTM Local Privilege Escalation Downgrade attack Microsoft (Windows) James Forshaw (@tiraniddo) Bug Bounty2022-10-272023-06-13
893Abusing Windows’ tokens to compromise Active Directory without touching LSASS Local Privilege Escalation Windows Active Directory Privilege Escalation NA Aurélien Chalot (@Defte_) Bug Bounty2022-10-272023-06-13
889Technical Analysis of Windows CLFS Zero-Day Vulnerability CVE-2022-37969 - Part 1: Root Cause Analysis Local Privilege Escalation Windows Microsoft Zscaler Threatlabz (@Threatlabz) Bug Bounty2022-10-282023-06-13
856Exploring ZIP Mark-of-the-Web Bypass Vulnerability (CVE-2022-41049) Local Privilege Escalation Windows Microsoft Kuba Gretzky (@mrgretzky) Bug Bounty2022-11-082023-06-13
844Unit 42 Finds Three Vulnerabilities in OpenLiteSpeed Web Server RCE OS command injection Path traversal Local Privilege Escalation LiteSpeed Artur Avetisyan (@3v1LMonk3y) Bug Bounty2022-11-102023-06-13
842Windows Kernel: Exploit CVE-2022-35803 in Common Log File System Windows Local Privilege Escalation Type confusion Microsoft luckyu (@uuulucky) Bug Bounty2022-11-112023-06-13
837CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS MacOS Local Privilege Escalation SIP bypass Apple Mickey Jin (@patch1t) Bug Bounty2022-11-112023-06-13
833CVE-2022-32929 - Bypass iOS backup%27s TCC protection Local Privilege Escalation TCC bypass MacoS iOS Apple Csaba Fitzl (@theevilbit) Bug Bounty2022-11-142023-06-13
810macOS Sandbox Escape vulnerability via Terminal MacOS Sandbox escape Local Privilege Escalation Apple Wojciech Reguła (@_r3ggi) Bug Bounty2022-11-182023-06-13
760discord.exe – Improper Input Validation Security code review Local Privilege Escalation Phishing Discord RiotSecTeam (@RiotSecTeam) Bug Bounty2022-11-282023-06-13
756Brocade Fabric OS ≤ v8.0.2c rbash escape to read system files rbash escape Local Privilege Escalation Broadcom Bitcrack (@bitcrack_cyber) Bug Bounty2022-11-292023-06-13