
CVE-2019-12889
Proof-of-concept exploit for CVE-2019-12889, demonstrating unauthenticated privilege escalation from Windows logon screen to NT AUTHORITY\System via…

Proof-of-concept exploit for CVE-2019-12889, demonstrating unauthenticated privilege escalation from Windows logon screen to NT AUTHORITY\System via…

Windows token theft and privilege escalation tool that steals leaked tokens from processes, enables SYSTEM-level access, user impersonation, and…

A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its…

VM Escape for Parallels Desktop <18.1.1

🔒 Modern C2 Platform with Cloudflare Tunnel Integration | WinRM & SSH Remote Management | Real-time Terminal & Remote Desktop | Built with FastAPI &…

POC for CVE-2020-10665 Docker Desktop Local Privilege Escalation

A vulnerability has been identified in Docker Desktop. A remote attacker could exploit this vulnerability to trigger security restriction bypass on…

A script to automate keystrokes through a graphical desktop program.

Plantronics Desktop Hub LPE

VM Escape for Parallels Desktop <18.1.1

Parallels Desktop privilege escalation - CVE-2023-50226 / ZDI-CAN-21227

Windows Remote Desktop Services Vulnerability Allows Remote Code Execution

Local Privilege Escalation PoC to pop a SYSTEM shell for CVE-2019-9702 in Symantec Encryption Desktop.

Proof-of-concept exploit for Docker Desktop for Windows privilege escalation (CVE-2020-11492). Uses named pipe impersonation to steal SYSTEM token…

Proof-of-concept for Docker Desktop for Windows privilege escalation (CVE-2020-11492). Exploits named pipe impersonation to achieve SYSTEM-level…

Master's Thesis research on CVE-2024-30051 (Windows DWM Heap Overflow). Features a high-reliability exploit with automated heap spray optimization,…

Weaponizes a Visual-Field Singularity in Windows Desktop Window Manager to achieve local privilege escalation to SYSTEM, bypassing Graphics Isolation…

Proof-of-concept exploit for CVE-2022-25365, a privilege escalation vulnerability in Docker Desktop for Windows via named pipe impersonation.