writeups.xyz writeups.xyz / Thick Client

Title Vulnerabilities Programs Authors
Evernote RCE: From PDF.js font-injection to All-platform Electron exposed ipcRenderer with listened BrokerBridge Remote-Code Execution
Exploiting Steam: Usual and Unusual Ways in the CEF Framework
Shipping your Private Key - CVE-2023-43870, Paxton do a Lenovo
Bitwarden Heist - How To Break Into Password Vaults Without Using Passwords
CVE-2023-22524: RCE Vulnerability in Atlassian Companion for macOS
macOS Atlassian Companion Remote Code Execution
LibreOffice Arbitrary File Write (CVE-2023-1883)
VSCode Remote Code Execution advisory
KeePass Master Password Exploit - CVE-2023-32784 - Proof Of Concept (POC)
Parallels Desktop Toolgate Vulnerability
Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 1
CVE from 2018 Strikes Again
CVE-2023-24068 && CVE-2023-24069: Abusing Signal Desktop Client for fun and for Espionage
Operation Crack: Hacking IDA Pro Installer PRNG from an Unusual Way
Thick Client — Attacking databases the fun/easy way