
CVE-2021-36934-DLL-Hijacking-DFIR-Investigation
DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

Project for tracking publicly disclosed DLL Hijacking opportunities.

Exploiting the .lnk vulnerability and operating system handling mechanisms regarding explorer.exe and USB drives.

CVE-2026-50343 InstallService StaticPluginMap EoP - standard user to SYSTEM

Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar…

Robber is open source tool for finding executables prone to DLL hijacking

CVE-2021-34527 AddPrinterDriverEx() Privilege Escalation

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

CVE-2025-56383-Proof-of-Concept

It shook the world in 2017 and has evolved into today’s CVE‑2025‑2776. Microsoft still relies on SMBv1, this article will explain how attackers have…

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

Helakuru Version 1.1 DLL Hijack - CVE-2024-48605

CVE-2023-6401 is a DLL hijacking vulnerability that allows attackers to execute arbitrary code by placing a malicious `dbghelp.dll` file in the…

We found a way to DLL sideload with cleanmgr.exe

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

Proof of concept (exploit) for CVE-2024-6473

PoC for LPE with QlikView