writeups.xyz writeups.xyz / Microsoft

Title Vulnerabilities Programs Authors
Gaining Unlimited access to graph AuditLogs endpoint using complex filters with non-privileged user account
XSLeaking with my best bud SOP
Abusing Azure Hybrid Workers for Privilege Escalation – Part 2: An Azure PrivSec Story
Inside the Black Box | How We Fuzzed Microsoft Defender for IoT and Found Multiple Vulnerabilities
CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed)
MSRC – Joint security research write up – Azure AD Consent bypass disclosure with Kim Jamia – Q1/2022
Azure Active Directory Exposes Internal Information
Debugging the undebuggable and finding a CVE in Microsoft Defender for Endpoint
Pwning Microsoft Azure Defender for IoT | Multiple Flaws Allow Remote Code Execution for All
Targeting Visual Studio Code for macOS: File Discovery and a TCC bypass (kinda)
CVE-2022-0337 System environment variables leak on Google Chrome, Microsoft Edge and Opera
Insecure Direct Object Reference Exposes all users of Microsoft Azure Independent Software Vendors
Git honours embedded bare repos, and exploitation via core.fsmonitor in a directory's .git/config affects IDEs, shell prompts and Git pillagers
Securing Developer Tools: Git Integrations
SSD Advisory – Exchange Server GetWacInfo Information Disclosure Vulnerability
I have Found Microsoft Subdomain Website database list, database username, password
Escalating from Logic App Contributor to Root Owner in Azure
AutoWarp: Critical Cross-Account Vulnerability in Microsoft Azure Automation Service
Skype extension: All functionality broken? Still exploitable!
Microsoft Team’s Unpatched URL Spoofing Vulnerability
How Docker Made Me More Capable and the Host Less Secure
SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999)
Microsoft OneDrive For Macos Local Privilege Escalation
CVE-2020-0696 - Microsoft Outlook Security Feature Bypass Vulnerability
First Valid BUG Finding At Microsoft And I Got the Acknowledgments Page Microsoft