Subscribe via feed.
Archive for July, 2021

Microsoft Hyper-V vmswitch.sys Proof Of Concept

Posted by deepcore under exploit (No Respond)

This is a proof of concept for CVE-2021-28476 (“Hyper-V Remote Code Execution Vulnerability”), an arbitrary memory read in vmswitch.sys (network virtualization service provider) patched by Microsoft in May 2021.

Realtek RTKVHD64.sys Out-Of-Bounds Access

Posted by deepcore under exploit (No Respond)

Proof of concept exploit for an out-of-bounds access vulnerability in the Realtek RTKVHD64.sys, leading to pool corruption.

Windows TCP/IP Denial Of Service

Posted by deepcore under exploit (No Respond)

This is a proof of concept for a Windows TCP/IP denial of service vulnerability due to a NULL dereference in tcpip.sys. This was patched by Microsoft in February 2021. It is triggerable remotely by sending malicious UDP packet over IPv6.

XNU Network Stack Kernel Heap Overflow

Posted by deepcore under exploit (No Respond)

XNU suffers from a network stack kernel heap overflow due to an out-of-bounds memmove in 6lowpan. Proof of concept code included.

Microsoft Windows CreateProcessWithLogon Write Restricted Service Privilege Escalation

Posted by deepcore under exploit (No Respond)

Microsoft Windows has an issue where you can use the CreateProcessWithLogon API to escape a write restricted service and achieve full write access as the service user.

Schneider Electric EVlink Charging Stations Authentication Bypass / Code Execution

Posted by deepcore under exploit (No Respond)

Multiple Schneider Electric EVlink Charging Stations suffers from authentication bypass and remote code execution vulnerabilities.

[webapps] osCommerce 2.3.4.1 – Remote Code Execution (2)

Posted by deepcore under Security (No Respond)

osCommerce 2.3.4.1 – Remote Code Execution (2)

Tags: ,

[webapps] WordPress Plugin Popular Posts 5.3.2 – Remote Code Execution (RCE) (Authenticated)

Posted by deepcore under Security (No Respond)

WordPress Plugin Popular Posts 5.3.2 – Remote Code Execution (RCE) (Authenticated)

Tags: ,

Apache Tomcat 9.0.0M1 Open Redirect

Posted by deepcore under exploit (No Respond)

These are details on an open redirection vulnerability in Apache Tomcat version 9.0.0M1 that was discovered in 2018.

Apache Tomcat 9.0.0.M1 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

These are details on a cross site scripting vulnerability in Apache Tomcat version 9.0.0M1 that was discovered in 2019.