writeups.xyz writeups.xyz / Microsoft

Title Vulnerabilities Programs Authors
CVE-2022-30136: Microsoft Windows Network File System V4 Remote Code Execution Vulnerability
Microsoft Teams — Cross Site Scripting (XSS) Bypass CSP
Microsoft Azure Site Recovery DLL Hijacking
Visual Studio Code - Remote Code Execution in Restricted Mode (CVE-2021-43908)
Bypassing .NET Serialization Binders
FabricScape: Escaping Service Fabric and Taking Over the Cluster
HTML and Hyperlink Injection via Share Option In Microsoft Onenote Application
Pwn2Own 2021 Microsoft Exchange Exploit Chain
Proofpoint Discovers Potentially Dangerous Microsoft Office 365 Functionality that can Ransom Files Stored on SharePoint and OneDrive
That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability
Privilege Escalation in AKS Clusters
Hertzbleed Attack
SynLapse – Technical Details for Critical Azure Synapse Vulnerability
Microsoft Azure Synapse Pwnalytics
A Story of a Bug Found Fuzzing
CVE-2022-26937: Microsoft Windows Network File System NLM Portmap Stack Buffer Overflow
Microsoft Dynamics Container Sandbox RCE via Unauthenticated Docker Remote API 20,000$ Bounty
Spoofing Microsoft 365 Like It’s 1995
How I was able to down a service of Microsoft ? Denial of Service (DOS) Attack on Microsoft.
Kubernetes Privilege Escalation: Excessive Permissions in Popular Platforms
Hacking Swagger-UI - from XSS to account takeovers
New Wine in Old Bottle - Microsoft Sharepoint Post-Auth Deserialization RCE (CVE-2022-29108)
Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923)
Wiz Research discovers "ExtraReplica"— a cross-account database vulnerability in Azure PostgreSQL
Azure Monitor – Malicious KQL Query