Bugs & Advisories

Bugs found during client work. The affected companies can't be named, I can discuss technical details where permitted.
TitleTargetImpactDate
LPE via Insecure File Permissions (Service DLL Replacement)Privileged Windows serviceCode execution as SYSTEM2026
Stack-Based Buffer Overflow in Privileged Logging HandlerPrivileged Windows serviceCode execution as SYSTEM2024
Format String Vulnerability in Logging ComponentEndpoint security productMemory disclosure / corruption2024
Integer Overflow in Kernel Entropy RoutineWindows kernel driverKernel denial of service2024
Heap Buffer Overflow in Privileged Local RPC ServicePrivileged RPC serviceCode execution as SYSTEM2023
LPE via Arbitrary Write and Self-Protection BypassEndpoint security productCode execution as SYSTEM2023
Arbitrary Write Primitive via Insecure Mount-Point HandlingPrivileged Windows serviceArbitrary file write -> SYSTEM2023
RPC Authorization Bypass Enables Unprivileged Service AccessPrivileged RPC servicePrivilege boundary bypass2023
Self-Protection Bypass via Minifilter Logic FlawWindows minifilter driverSecurity control bypass2023
LPE via Unprivileged Database ModificationEndpoint security clientCode execution as SYSTEM2023
Weak Database ACLs Allow Unprivileged ModificationEndpoint security clientIntegrity / configuration bypass2023
Out-of-Bounds Write via Insufficient IOCTL ValidationOEM kernel driverKernel memory corruption2022
Out-of-Bounds Read/Write via Insufficient IOCTL ValidationOEM kernel driverKernel memory disclosure / corruption2022
LPE via TOCTOU in Vendor Update ServicePrivileged Windows serviceCode execution as SYSTEM2022
Integer Overflow in Privileged Optimization ServicePrivileged Windows serviceMemory corruption2022
Arbitrary Delete Primitive via Insecure Mount-Point HandlingPrivileged Windows serviceArbitrary file delete2022
Unprotected Named Pipe Exposes Privileged InterfaceWindows IPC / named pipeAuthorization bypass2021