
CVE-Vulnerability-Research-Exploit-Analysis
Researched and executed real-world CVE exploits in a controlled sandbox: CVE-2000-0168 DoS on Windows 95, ARP Spoofing with NTLMv2 credential…

Researched and executed real-world CVE exploits in a controlled sandbox: CVE-2000-0168 DoS on Windows 95, ARP Spoofing with NTLMv2 credential…

Proof-of-concept exploit for CVE-2015-1769 using a crafted VHD file and symbolic link to trigger a Windows privilege escalation via Mount Manager.

Exploit for CVE-2024-40586: coerces Windows hosts to authenticate via a vulnerable FortiClient named pipe, enabling privilege escalation to SYSTEM or…

PunkBuster LPI to NT AUTHORITY\SYSTEM

Proof-of-concept exploit for CVE-2020-27955 in Git-LFS, demonstrating remote code execution via a crafted git clone operation to obtain a reverse…

The DCERPC only printerbug.py version

包括能执行的命令探测和一键getshell(需要服务器部署服务)

An exploitation demo of Outlook Elevation of Privilege Vulnerability

CVE-2025-33073

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

Zeek package for detecting PetitPotam NTLM relay attacks via EFS DCERPC over unencrypted SMB, distinguishing successful and unsuccessful exploit…

CVE-2020-13941: Abusing UNC Paths in Windows Environments in Apache Solr

Proof-of-concept exploit for a local privilege escalation vulnerability in Datacard XPS Card Printer Driver via insecure file permissions and DLL…

Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework

VMware Aria Operations for Logs CVE-2023-34051

PoC for CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation

CVE-2019-1040 with Kerberos delegation

Proof-of-concept for CVE-2024-37726: local privilege escalation in MSI Center via arbitrary file overwrite using symlink/junction attacks and OpLock…