Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1278Symlinks as mount portals: Abusing container mount points on MikroTik%27s RouterOS to gain code execution Container escape Local Privilege Escalation MikroTik nns Bug Bounty2022-08-052023-06-13
1277CVE-2022-31660 and CVE-2022-31661 (FIXED): VMware Workspace ONE Access, Identity Manager, and vRealize Automation LPE Local Privilege Escalation VMware Spencer McIntyre (@zeroSteiner) Bug Bounty2022-08-052023-06-13
1276Revisiting OMI: Analysis of CVE-2022-29149, a privilege escalation vulnerability in Azure OMI Local Privilege Escalation Cloud Microsoft Nir Ohfeld (@nirohfeld) Bug Bounty2022-08-052023-06-13
1264From Shared Dash to Root Bash :: Pre-Authenticated RCE in VMWare vRealize Operations Manager Authentication bypass Information disclosure Local Privilege Escalation VMware Steven Seeley (@steventseeley) Bug Bounty2022-08-092023-06-13
1261The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I) Memory corruption Race condition Local Privilege Escalation Android Linux Kernel Organization Google Samsung Xingyu Jin Bug Bounty2022-08-102023-06-13
1249Rapid7 Discovered Vulnerabilities in Cisco ASA, ASDM, and FirePOWER Services Software RCE OS command injection Local Privilege Escalation MiTM Cisco Jake Baines (@Junior_Baines) Bug Bounty2022-08-112023-06-13
1247Attacking Titan M with Only One Byte Memory corruption Local Privilege Escalation Google Damiano Melotti (@DamianoMelotti) Bug Bounty2022-08-112023-06-13
1246The cloud has an isolation problem: PostgreSQL vulnerabilities affect multiple cloud vendors Privilege escalation Cross-tenant vulnerability OS command injection Local Privilege Escalation Cloud Google Microsoft Aiven Shir Tamari (@shirtamari) Bug Bounty2022-08-112023-06-13
1245IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit Authentication bypass Information disclosure CSRF RCE Local Privilege Escalation VMware Steven Seeley (@steventseeley) Bug Bounty2022-08-112023-06-13
1241Process injection: breaking all macOS security layers with a single vulnerability Local Privilege Escalation Process injection vulnerability Apple Thijs Alkemade (@xnyhps) Bug Bounty2022-08-122023-06-13
1226Hacking Zyxel IP cameras to gain a root shell Missing authentication DoS Information disclosure Local Privilege Escalation Zyxel Eric Urban Bug Bounty2022-08-142023-06-13
1216FreeBSD 11.0-13.0 LPE via aio_aqueue Kernel Refcount Bug Memory corruption Local Privilege Escalation FreeBSD Security Team Chris (@accessvector) Bug Bounty2022-08-162023-06-13
1190Vulnerability in Linux containers – investigation and mitigation Local Privilege Escalation Moby Project Steven Murdoch (@sjmurdoch) Bug Bounty2022-08-222023-06-13
1187Break Me Out Of Sandbox In Old Pipe - CVE-2022-22715 Windows Dirty Pipe Local Privilege Escalation Microsoft k0shl (@KeyZ3r0) Bug Bounty2022-08-232023-06-13
1175SSD Advisory – VhdmpiValidateVirtualDiskSurface LPE Local Privilege Escalation Windows Sana Oshika (@bigshika) Bug Bounty2022-08-262023-06-13
1160Blind Exploits To Rule Watchguard Firewalls XPath injection Memory corruption Local Privilege Escalation RCE WatchGuard Charles Fol (@cfreal_) Bug Bounty2022-08-292023-06-13
1152CVE-2022-26113: FortiClient Arbitrary File Write As SYSTEM Arbitrary file write Local Privilege Escalation Fortinet David Yesland (@daveysec) Bug Bounty2022-08-302023-06-13
1146SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250) Memory corruption Local Privilege Escalation Ubuntu Linux Kernel Organization Cedric Halbronn (@saidelike) Bug Bounty2022-09-012023-06-13
1143Azure Synapse: Local Privilege Escalation Vulnerability in Spark Race condition Local Privilege Escalation Cloud Microsoft Tzah Pahima (@TzahPahima) Bug Bounty2022-09-012023-06-13
1141Google & Apache Found Vulnerable to GitHub Environment Injection Privilege escalation CI/CD Google Apache Noam Dotan Bug Bounty2022-09-012023-06-13
1133Simple IBM I (AS/400) Hacking Local Privilege Escalation Midrange system Menu security NA pz Bug Bounty2022-09-052023-06-13
1132SSD Advisory – Linux CONFIG_WATCH_QUEUE LPE Memory corruption Race condition Local Privilege Escalation Ubuntu Linux Kernel Organization - Bug Bounty2022-09-052023-06-13
1131Hacking My Helium Crypto Miner Hardcoded credentials Missing authentication RCE Local Privilege Escalation Pycom Md. Asif Hossain (@0x0asif) Bug Bounty2022-09-052023-06-13
1120Quasar: Compromising Electron Apps Local Privilege Escalation Microsoft Taggart (@mttaggart) Bug Bounty2022-09-062023-06-13
1106Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution Arbitrary Code Execution Local Privilege Escalation AVEVA Daan Keuper (@daankeuper) Bug Bounty2022-09-082023-06-13