ProxyLogon (CVE-2021-26855+CVE-2021-27065) Exchange Server RCE (SSRF->GetWebShell)
Educational Follina PoC Tool
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.
MSDT 0-Day Mass Exploitation Tool
unauthorized RcE exploit for webnin < 1.920
A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor
follina zero day vulnerability to help Microsoft to mitigate the attack
Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files
WebLogic CNVD-C-2019_48814 CVE-2017-10271 Scan By 7kbstorm
Python file scanner created in 2021 scanning for known and potential vulns
CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina
An Unofficial Patch Follina CVE-2022-30190 (patch) by micrisoft Guidelines. for more details goto : https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/
Python3 code to exploit CVE-2019-15107 and CVE-2019-15231
These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)
Axios Redos (CVE-2021-3749) proof of concept
These are two Python scripts compiled to easily and quickly apply temporary protection against the CVE-2022-30190 vulnerability (Follina)
this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.
proof of concept to CVE-2022-30190 (follina)
CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina