writeups.xyz writeups.xyz / TOCTOU

Title Vulnerabilities Programs Authors
Firmware Security: Alcatel-Lucent ALE-DeskPhone
The Nightmare of Apple's OTA Update: Bypassing the Signature Verification and Pwning the Kernel
Getting SYSTEM on Windows in style
CVE-2023-38146: Arbitrary Code Execution via Windows Themes
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586)
Escaping Parallels Desktop with Plist Injection
Avast Anti-Virus privileged arbitrary file create on virus quarantine (CVE-2023-1585 and CVE-2023-1587)
Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2
SSRF via DNS Rebinding (CVE-2022–4096)