
CVE-2021-1675
CVE-2021-1675 Detection Info
curated-resourceseducationexploitation+4
2143 years ago

CVE-2021-1675 Detection Info

PoC for CVE-2022-41120/CVE-2022-44704: arbitrary file delete/write in Sysmon via ClipboardChange RPC leading to local privilege escalation on Windows.

Proof-of-concept exploit for arbitrary file write in Sysmon 14.14, abusing Windows service tracing to achieve privilege escalation.

Splunk SIEM lab simulating and detecting CVE-2021-34527 (PrintNightmare) exploitation using Sysmon, Windows Event logs, and custom SPL detection…