/explore

Click through on any links that interest you or select the planets on the right to continue exploring the Outer Web.
You are here

seclists.org
| | packetstormsecurity.com
3.1 parsecs away

Travel
| | Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
| | m417z.com
2.7 parsecs away

Travel
| | This is a write-up of a vulnerability that I discovered in Windows. The vulnerability was patched in December's Patch Tuesday, and the CVE assigned to it is CVE-2023-36003. The vulnerability allows a non-elevated process to inject a DLL into an elevated or otherwise inaccessible process, allowing for privilege escalation. The vulnerability is caused by a lack of security checks in the InitializeXamlDiagnosticsEx API, which is used for inspecting applications that use Extensible Application Markup Language (XAML) for their UI. XAML is the recommended way to build user interfaces in new Windows applications, and is used by more and more built-in applications, including Task Manager and Windows Terminal.
| | www.atredis.com
2.8 parsecs away

Travel
| | [AI summary] A detailed technical write-up analyzes a Windows Standard Collector Service privilege escalation vulnerability involving symlink attacks and arbitrary file creation, includes a proof-of-concept exploit, and describes the patch.
| | www.cyberkendra.com
13.7 parsecs away

Travel
| Spring4Shell: Spring core RCE vulnerability