
CVE-2020-3433
PoCs and technical analysis for three Cisco AnyConnect Windows vulnerabilities: local privilege escalation (CVE-2020-3433), denial of service…

PoCs and technical analysis for three Cisco AnyConnect Windows vulnerabilities: local privilege escalation (CVE-2020-3433), denial of service…

Proof-of-concept exploit for CVE-2024-36877 targeting firmware vulnerabilities, with detailed write-up and binary exploitation techniques.

Proof-of-concept exploit for Adobe Reader type confusion leading to heap overflow, with detailed root-cause analysis and detection guidance.

Proof-of-concept exploit for CVE-2024-21338, a kernel vulnerability. Demonstrates exploitation technique for security research and vulnerability…

Challenge handouts, source code, and solutions for UofTCTF 2025

Windows kernel driver exploits for HackSys Extreme Vulnerable Driver, demonstrating binary exploitation and privilege escalation for security…

Proof-of-concept exploit that bypasses ASLR on Intel CPUs by abusing branch target buffer and speculative execution to leak randomized addresses via…

Proof-of-concept exploit for CVE-2020-17008, demonstrating splWOW64 elevation of privilege via heap manipulation on Windows 10 and Server.

Educational analysis of WinRAR code execution vulnerability CVE-2023-38831, covering exploitation mechanics and mitigation strategies through…

Alternative Read and Write primitives using Rtl* functions the unintended way.

C++ exploit for CVE-2021-1732 targeting Windows privilege escalation on Win10 1803-20H2 and Server 2019/2004. Provides kernel-level elevation of…

Exploit for CVE-2022-4262, a Chromium browser vulnerability. Includes references to official bug report, in-the-wild exploit analysis, and root cause…

Kernel privilege escalation exploit for CVE-2026-31431, abusing AF_ALG interface to overwrite /bin/su and spawn a root shell. Includes C…

Reflective PE loader written in Zig. Loads and executes native and .NET PE files directly from memory.

This repository contains the sources and documentation for the SWAPGS attack PoC (CVE-2019-1125)

BOF implementations of CVE-2024-26229 for Cobalt Strike and BruteRatel

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

CVE-2022-0185 POC and Docker and Analysis write up