
SCCM-CVE-2026-47301-Remote-Code-Execution-Exploit
Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Payload for DLL sideloading of the OneDriveUpdater.exe, based on the PaloAltoNetwork Unit42's blog post

A small tool I made to dump the export table of PE files. The primary use case was intended for use within DLL proxying.

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

Code Execution & Persistence in NETWORK SERVICE FAX Service

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

Lockbit3.0 Microsoft Defender MpClient.dll DLL Hijacking PoC

Lateral Movement Using DCOM and DLL Hijacking

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

For when DLLMain is the only way

Execute shellcode files with rundll32

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege
