
CVE-2026-66804
Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Proof-of-concept exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a broken access, CAB arbitrary-write path…

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Windows Local Privilege Escalation via CdpSvc service (Writeable SYSTEM path Dll Hijacking)

Autoelevate DLL search-order hijacking UAC bypass for x64 Windows 7–11, abusing 32-bit iscsicpl.exe via SysWOW64 to execute code without a UAC prompt.

Code Execution & Persistence in NETWORK SERVICE FAX Service

CompMgmtLauncher & Sharepoint DLL Search Order hijacking UAC/persist via OneDrive

Reflective DLL to privesc from NT Service to SYSTEM using SeImpersonateToken privilege


RemoteDLLInjector

A session-0 capable dll injection utility

Local & remote Windows DLL Proxying

Passive UAC elevation using dll infection

A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.