
HackSysDriverExploits
Windows kernel driver exploits for HackSys Extreme Vulnerable Driver, demonstrating binary exploitation and privilege escalation for security…

Windows kernel driver exploits for HackSys Extreme Vulnerable Driver, demonstrating binary exploitation and privilege escalation for security…

Demonstrates exploitation of AMD μProf driver (CVE-2023-20562) for privilege escalation via EPROCESS token write and DSE bypass, enabling unsigned…

Proof-of-concept exploit for CVE-2015-2546, with accompanying research paper and blog detailing the vulnerability analysis and exploitation technique.

Educational lab for understanding Java deserialization vulnerabilities with PoC exploits for JBoss CVEs, gadget chain analysis, and a vulnerable HTTP…

Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation,…

Deep-dive analysis and exploitation walkthrough of CVE-2016-4622, a WebKit JavaScriptCore memory disclosure vulnerability via Array.slice TOCTOU race…

Proof-of-concept exploit for CVE-2025-6554, demonstrating V8 sandbox escape via addressof and fakeobj primitives to achieve arbitrary read/write.…

Proof-of-concept exploit for CVE-2023-41993, demonstrating a WebKit vulnerability with post-exploitation techniques and binary exploitation…

Educational Linux kernel exploit for CVE-2024-1086, demonstrating privilege escalation via an nftables double-free vulnerability in netfilter.

BYOVD exploitation framework for CVE-2022-22077 targeting RTCore64.sys. Demonstrates kernel token theft, privilege escalation to SYSTEM, and C2…

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite…

Reproduction of CVE-2016-5195 (Dirty COW) Linux local privilege escalation exploit. Provides a ready-to-compile C source and step-by-step execution…

Proof-of-concept exploit targeting ARM TrustZone secure world, demonstrating a vulnerability in OP-TEE OS for educational and research purposes.

Educational exploit for CVE-2022-2588, a Linux kernel race condition leading to privilege escalation. Includes Vagrant setup for a vulnerable machine…

Curated CTF writeup collection for GlacierCTF 2023 covering pwn, rev, web, crypto, and smart contract challenges with solutions and educational…

Arbitrary physical memory read/write exploitation using ThrottleStop.sys (CVE-2025-7771) with superfetch address translation - Windows kernel…

Educational analysis of CVE-2024-9680, a use-after-free vulnerability in Firefox's CSS Animation Timeline, with detailed exploit mechanics and…