ALPC161 CVE-2020-1027: Windows CSRSS Heap Buffer Overflow and Sandbox Escape
CVE-2020-1027 is a heap buffer overflow in the Windows CSRSS SxS assembly component. A missing bounds check on UNICODE_STRING.MaximumLength in an ALPC…
ALPC161 CVE-2020-1027 is a heap buffer overflow in the Windows CSRSS SxS assembly component. A missing bounds check on UNICODE_STRING.MaximumLength in an ALPC…
RPC147 Many Windows RPC servers expose several context-handle types under one interface. When the IDL marks a handle as FC_BIND_CONTEXT (0x70) instead of…
Network120 A length-confusion bug in OpenBSD's PAP handler let an unauthenticated attacker on the same broadcast domain pass authentication with zero-length credentials —…
Security140 Squidbleed (CVE-2026-47729) is a heap buffer over-read in the Squid proxy's FTP gateway, rooted in a missing NUL-terminator check before strchr() that…
Exploit Development134 CVE-2026-41096 is a remotely-triggerable heap overflow in dnsapi.dll. A single crafted UDP DNS response with QDCOUNT=0 corrupts 604 bytes past a heap…
AI Security Research214 Andy Gill's ZephrSec write-up of an autonomous vulnerability hunting system built around Claude Code and the Model Context Protocol: 8 MCP servers,…
Vulnerability Analysis133 An independent PoC reliably bug-checks Windows 11 25H2 (26100.8655) by spraying malformed batched virtualisation-mapping messages at bindflt.sys, faulting inside BfValidateShortName at +0x23783.…
Exploit Development129 Eleven months after RarLab shipped WinRAR 7.13 to fix CVE-2025-8088, two Russia-aligned APT clusters (Earth Dahu / Gamaredon and SHADOW-EARTH-066 / UAC-0226)…
Exploit Development73 Meeting-room cameras and conference-room tablets are some of the least-monitored, most insecurely-configured attack surfaces in an enterprise. Spaceraccoon (Eugene Lim) walks through…
Cryptography105 Trail of Bits and the badkeys project found hundreds of RSA and DSA keys in the wild whose moduli have regularly spaced…
Exploit Development177 CVE-2026-40369 is an unprivileged arbitrary 12-byte kernel write in nt!ExpGetProcessInformation, reachable from Chrome/Edge/Firefox renderer sandboxes via NtQuerySystemInformation. A walk through the unchecked…
Exploit Development265 CVE-2018-8611 is a race-condition LPE in the Windows Kernel Transaction Manager (KTM), originally caught in the wild by Kaspersky’s AEP in October…