
MSRKit
A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)

A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)

Local privilege escalation exploit for Redmi K50G/POCO F4 GT using CVE-2026-43499 (futex UAF) to gain temporary root and load KernelSU without…

C exploit for CVE-2026-31431, a Linux kernel page-cache corruption vulnerability in the AF_ALG AEAD path, using splice() to influence cached file…

Project Date : Feb 2026 / Memory corruption vulnerability within the kernel driver of MiniTool. Demonstrates a debugger-assisted arbitrary kernel…

Using CVE-2021-40449 to manual map kernel mode driver

Local Windows kernel privilege escalation exploit for CVE-2018-8611 (KTM UAF) using write-what-where and increment primitives.

Local privilege escalation PoC for Windows CVE-2026-66804 using CrossDevice DLL planting and SigmaPotato token impersonation to spawn a SYSTEM…

Windows KASLR bypass using prefetch side-channel

Unlock the Meta Quest 1 bootloader and gain root access using GhostLock + CVE-2021-1931.

Post exploitation technique to turn arbitrary kernel write / increment into full read/write primitive on Windows 11 22H2

PoC exploiting Aligned Chunk Confusion on Windows kernel Segment Heap

Windows kernel exploit for CVE-2020-17057 using palette objects with dangling data pointers, targeting type isolation bypass for privilege escalation.

WNF Code Execution Library Using C#

Code execution/injection technique using DLL PEB module structure manipulation

Proof-of-concept exploit for CVE-2022-26809, a Windows RPC runtime integer overflow vulnerability. Includes trigger scripts using PetitPotam-style…

Exploit systems using older WinRAR without knowing their username (unlike other projects)

Using CVE-2019-0708 to Locally Promote Privileges in Windows 10 System

PoC and analysis for CVE-2022-26809, a Windows RPC runtime integer overflow vulnerability. Includes trigger scripts using PetitPotam-style UNC path…