Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
425Multiple vulnerabilities in Nokia BTS Airscale ASIKA Base transceiver station Path traversal Hardcoded private key Local Privilege Escalation Security misconfiguration Nokia Geoffrey Bertoli (@YofBalibump) Bug Bounty2023-02-212023-06-13
422Trellix Advanced Research Center Discovers a New Privilege Escalation Bug Class on macOS and iOS Local Privilege Escalation Apple (macOS) Austin Emmitt (@alkalinesec) Bug Bounty2023-02-212023-06-13
396From CVE-2022-33679 to Unauthenticated Kerberoasting Kerberos MiTM Local Privilege Escalation Downgrade attack Microsoft (Windows) Trampas Howe (@trampashowe) Bug Bounty2023-02-252023-06-13
394Give me a browser, I’ll give you a Shell Local Privilege Escalation Kiosk hacking NA Rend Bug Bounty2023-02-252023-06-13
356Bypass TCC via iCloud TCC bypass Local Privilege Escalation Apple (macOS) Wojciech Reguła (@_r3ggi) Bug Bounty2023-03-042023-06-13
326Leveraging ssh-keygen for Arbitrary Execution (and Privilege Escalation) Local Privilege Escalation IoT NA Sean Pesce (@SeanPesce) Bug Bounty2023-03-092023-06-13
309Veeam Backup and Replication CVE-2023-27532 Deep Dive Local Privilege Escalation Veeam James Horseman (@JamesHorseman2) Bug Bounty2023-03-132023-06-13
306Your Browser is Not a Safe Space Local Privilege Escalation Lateral movement NA Corey Ham Bug Bounty2023-03-142023-06-13
276Windows Installer EOP (CVE-2023-21800) Local Privilege Escalation Microsoft (Windows) Adrian Denkiewicz Bug Bounty2023-03-212023-06-13
261Dynamic Linking Injection and LOLBAS Fun DLL Hijacking Dynamic-linking injection Local Privilege Escalation NA Joseph Henry Bug Bounty2023-03-282023-06-13
233CyberGhostVPN - the story of finding MITM, RCE, LPE in the Linux client RCE MiTM Local Privilege Escalation CyberGhost mmmds Bug Bounty2023-04-032023-06-13
228Windows Task Scheduler Application, Version 19044.1706 Advisory Unquoted search path Local Privilege Escalation Microsoft (Windows) Ben Lincoln (@0x00C651E0) Bug Bounty2023-04-042023-06-13
227Microsoft Intune, Version 1.55.48.0 Advisory Unquoted search path Local Privilege Escalation Microsoft (Intune) Ben Lincoln (@0x00C651E0) Bug Bounty2023-04-042023-06-13
224Bash Privileged-mode Vulnerabilities In Parallels Desktop And CDPATH Handling In MacOS MacoS Local Privilege Escalation Parallels Reno Robert (@renorobertr) Bug Bounty2023-04-062023-06-13
202CVE-2023-29383: Abusing Linux chfn to Misrepresent /etc/passwd Local Privilege Escalation shadow-utils Tom Neaves Bug Bounty2023-04-122023-06-13
180Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2 Local Privilege Escalation TOCTOU Arbitrary file write Docker Eviatar Gerzi Bug Bounty2023-04-192023-06-13
173The Fuzzing Guide to the Galaxy: An Attempt with Android System Services Android Fuzzing Heap overflow Integer overflow Out-of-bounds Write Memory corruption Local Privilege Escalation Samsung Anthony Remy Bug Bounty2023-04-202023-06-13
169CVE-2023-23525: Get Root via A Fake Installer Local Privilege Escalation Apple (macOS) Mickey Jin (@patch1t) Bug Bounty2023-04-202023-06-13
150Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587) TOCTOU NULL pointer dereference Arbitrary file write Local Privilege Escalation Avast Denis Skvortcov (@Denis_Skvortcov) Bug Bounty2023-04-262023-06-13
146Privilege Escalation in Microsoft Windows Local Privilege Escalation Microsoft (Windows) Tobias Neitzel (@qtc_de) Bug Bounty2023-04-282023-06-13
126CVE-2023-25394 - VideoStream Local Privilege Escalation Local Privilege Escalation Videostream Dan Revah (@danrevah) Bug Bounty2023-05-032023-06-13
120Bullied by Bugcrowd over Kape CyberGhost disclosure Local Privilege Escalation OS command injection Security code review Kape (CyberGhost) Ceri Coburn (@_ethicalchaos_) Bug Bounty2023-05-052023-06-13
111Escaping Parallels Desktop with Plist Injection Local Privilege Escalation Plist injection TOCTOU Parallels kn32 Bug Bounty2023-05-082023-06-13
95CVE-2023-26818 - Bypass TCC with Telegram in macOS TCC bypass Local Privilege Escalation Apple (macOS) Dan Revah (@danrevah) Bug Bounty2023-05-152023-06-13
92Finding and reporting a Gatekeeper bypass exploit with help from Mac Monitor GateKeeper bypass Local Privilege Escalation MacOS Apple (macOS) Brandon Dalton (@PartyD0lphin) Bug Bounty2023-05-152023-06-13