
CVE-2026-66804
Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

Code Execution & Persistence in NETWORK SERVICE FAX Service

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Lateral Movement Using DCOM and DLL Hijacking

For when DLLMain is the only way

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege

DLLirant is a tool to automatize the DLL Hijacking researches on a specified binary.

Remote DLL Injection with Timer-based Shellcode Execution