writeups.xyz writeups.xyz / Microsoft (Windows)

Title Vulnerabilities Programs Authors
Introducing Aladdin
From CVE-2022-33679 to Unauthenticated Kerberoasting
EoP via Arbitrary File Write/Overwite in Group Policy Client “gpsvc” – CVE-2022-37955
Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape vulnerability (CVE-2022-44666) (0day).
LPE via StorSvc
Dissecting and Exploiting TCP/IP RCE Vulnerability “EvilESP”
RC4 Is Still Considered Harmful
SSD Advisory – VhdmpiValidateVirtualDiskSurface LPE
Abusing Arbitrary File Deletes To Escalate Privilege And Other Great Tricks