
Lenovo-CVE-2025-8061
PoC for popping a system shell against the LnvMSRIO.sys driver

PoC for popping a system shell against the LnvMSRIO.sys driver

Passive UAC elevation using dll infection

A concept of using a ROP chain paired with a WRMSR primitive to call kernel functions and map unsigned drivers through BYOVD (AmdTools64.sys)


Proof-of-concept exploit for CVE-2026-46243, leveraging a fake NSS library and namespace manipulation to escalate privileges via cifs.upcall.

Exploits Scripts and other tools that are useful during Penetration-Testing or Red Team engagement

Cobalt Strike AggressorScripts CVE-2020-0796

all 4.4 ubuntu aws instances are vulnerable

Injects x64 managed DLLs into GUI processes via SetWindowsHook, with a modular C# payload runner and LSASS dump POC for red-team/offensive Windows…

Proof-of-concept exploit for CVE-2016-0051 (MS16-016) achieving local privilege escalation to SYSTEM on Windows 7, with compiled binaries and…

A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc

Exploits for the win32kfull!bFill vulnerability on Win10 x64 RS2 using Bitmap or Palette techniques

CVE-2020-11890: Improper input validations in the usergroup table class could lead to a broken ACL configuration to RCE

WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.

Exploit for CVE-2021-40449

A little tool to play with Kerberos.

Zimbra CVE-2022-27925 PoC

CVE-2020-0787的简单回显