exploits 🗡️
Exploit for CVE-2023-36802 targeting MSKSSRV.SYS driver
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
SeImpersonate privilege escalation tool for Windows 8 - 11 and Windows Server 2012 - 2022 with extensive PowerShell and .NET reflection support.
Proof-of-Concept for CVE-2023-38146 ("ThemeBleed")
POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.
PoC - Authenticated Remote Code Execution in VMware vCenter Server (Exploit)
POC for CVE-2024-40348. Will attempt to read /etc/passwd from target
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
Exploit targeting NT kernel in 24H2 Windows Insider Preview
Fully decrypt App-Bound Encrypted (ABE) cookies, passwords & payment methods from Chromium-based browsers (Chrome, Brave, Edge) - all in user mode, no admin rights required.
A delicious, but malicious SSL-VPN server 🌮
Kerberos relaying and unconstrained delegation abuse toolkit
Apache HTTP Server Vulnerability Testing Tool | PoC for CVE-2024-38472 , CVE-2024-39573 , CVE-2024-38477 , CVE-2024-38476 , CVE-2024-38475 , CVE-2024-38474 , CVE-2024-38473 , CVE-2023-38709
A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute arbitrary code remotely. This vulnerability arises fr…
LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49113
A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - …
Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability
POC exploit for CVE-2025-21333 heap-based buffer overflow. It leverages WNF state data and I/O ring IOP_MC_BUFFER_ENTRY
CVE-2025-24071: NTLM Hash Leak via RAR/ZIP Extraction and .library-ms File
WinRAR 0day CVE-2025-8088 PoC RAR Archive