
CVE-2026-66804
Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Code Execution & Persistence in NETWORK SERVICE FAX Service

A standalone DLL that exports databases in cleartext once injected in the KeePass process.

AAD related enumeration in Nim

freeBokuLoader fork which targets and frees Metsrv's initial reflective DLL package

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Lateral Movement Using DCOM and DLL Hijacking

Windows 10 DLL Injector via Driver utilizing VAD and hiding the loaded driver

For when DLLMain is the only way

Execute shellcode files with rundll32

A PoC demonstrating code execution via DLL Side-Loading in WinSxS binaries.

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege
