
CVE-2021-35211
Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

Make CVE-2020-0668 exploit work for version < win10 v1903 and version >= win10 v1903

POC : CVE-2023-21716 Microsoft Word RTF Font Table Heap Corruption

This repo contains all the work surrounding the development of the PoC for CVE-2024-48208, and how a simple OOB(Out-of-bound) read can result in jail…

Proof-of-concept exploit for CVE-2023-21716, a critical remote code execution vulnerability in Microsoft Word. Demonstrates exploitation of the…

CVE-2024-35250 PoC - Optimized & Condensed Form of Varwara's PoC

This package is not a complete root. It flips SELinux to Permissive and holds reclaim long enough for follow-on work. Host `uid=0` is not achieved…

Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption

Academic Research Edition - T1: User-mode evasion (obfuscation + syscall gateway), T2: BYOVD kernel bridge, T3: DMA hardware (future work).

Proof-of-concept exploit for CVE-2022-21971, an uninitialized pointer free vulnerability in Windows Runtime's prauthproviders.dll, triggered via…

PoC under work, CVE-2016-8823

An exploit to CVE-2020-0423, which is a Binder deffered work UAF.

Exploit work Privilege Escalation CVE-2017-1000112

CVE-2023-21716 - Microsoft Word RTF fonttbl Heap Corruption RCE exploit with reverse shell payload

CURRENTLY UNDER WORK... ALL I NEED TO IMPLEMENT IS JIT SPRAYING .....

fork of worawit/CVE-2021-3156 exploit_nss.py modified to work with ifconfig instead of the ip command

Microsoft Word 远程代码执行漏洞

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…