|
You are here |
googleprojectzero.blogspot.com | ||
| | | | |
itm4n.github.io
|
|
| | | | | Whenever a "new" DLL hijacking / planting trick is posted on Twitter, it generates a lot of comments. "It's not a vulnerability!" or "There is a lot of hijackable DLLs on Windows..." are the most common reactions. Though, people often don't really speak about the same thing, hence the overall confusion which leads us nowhere. I don't pretend to know the ultimate truth but I felt the need to write this post in order to hopefully clarify some points. | |
| | | | |
blog.0patch.com
|
|
| | | | | January 2023 Windows Updates brought a fix for CVE-2023-21541 , a local privilege elevation in Task Scheduler. The vulnerability was repo... | |
| | | | |
cihansol.com
|
|
| | | | | ||
| | | | |
pentestlab.blog
|
|
| | | Group policy preferences allows domain admins to create and deploy across the domainlocal users and local administrators accounts. This feature was introduced in Windows 2008 Server however it can be abused by an attacker since the credentials of theseaccounts are stored encrypted and the public key is published by Microsoft.This leaves the door open to... | ||