
CVE-2026-20841-PoC
Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

Security Research from the Microsoft Security Response Center (MSRC)

An experimentation and research platform to investigate the interaction of automated agents in an abstract simulated network environments.

8 Lessons, Kick-start Your Cybersecurity Learning.

Flow Integrity Deterministic Enforcement System. Mechanisms for securing AI agents with information-flow control.

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

Proof Of Concept for CVE-2023-21716 Microsoft Word Heap Corruption

"In-depth reverse engineering analysis of Vidar Stealer 2.0 covering Task Scheduler tampering (1999 timestamps), Explorer.exe process hollowing, and…

Investigates Microsoft Notepad RCE vulnerability CVE-2026-20841 through binary analysis and PoC exploit development for educational purposes.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Proof-of-concept exploit for Microsoft Defender Remote Code Execution Vulnerability (CVE-2021-1647) with password-protected payload archive.

AISec Plus Week 1 threat write-up — EchoLeak (CVE-2025-32711), zero-click indirect prompt injection in Microsoft 365 Copilot.

DESIGN AND IMPLEMENTATION OF A VULNERABILITY SCANNER FOR CVE-2026-45498 IN MICROSOFT DEFENDER

Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.

Technical analysis of CVE-2026-33825 (BlueHammer), a local privilege escalation vulnerability in Microsoft Defender, including exploitation flow,…

Microsoft Edge Elevation of Privilege Vulnerability

Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)

Technical analysis of CVE-2017-0037, a Microsoft browser memory corruption vulnerability enabling remote code execution via type confusion in CSS/JS…