master
Permissions.
Remove genericity, x64 and renamed stuff
Fix my screwup in winscp for servicename
Add an R in /Info for the trailer dictionary to make it readable
Permission changes (to sync)
Permissions
Add Main.swf from 593363c
added chm templates
changed dir names according to CVE
add ndkstager to data/exploits
Final changes before PR
Beautify and fix both ruby an AS
Change directory names
Initial commit of CVE-2013-3906
Use powershell instead of mshta
Add module for CVE-2013-5331
Cleanup linux/local/recvmmsg_priv_esc module
Do test
Add module for CVE-2014-0322
Add module for CVE-2014-0497
Delete debug
Update CVE-2014-0556
Unset debug flag
working exploit
Use PDWORD_PTR and DWORD_PTR
Add ppsx template
Change paths, add makefile and compile
Add module for CVE-2014-6352
Make last code cleanup
Update DLL
Add more targets
Allow more search space
This seems to work
Add support for Windows 8.1/Firefox
Disable debug
python 3 compatibility
revamped
Update exploit binaries for ms15-051
Clean template code
Add module for CVE-2015-3090
Add module for CVE-2015-3105
Add module for CVE-2015-3113
Remove sleep(), clean up WritableDir usage.
Update swf
Add support for Windows 10(10240) to CVE-2015-5122
Add Jenkins CLI Java serialization exploit module
working module
Re-add compiled Binary
Add a random sentinel to close channel when terminates (#1)
tomcat 8 priv esc on ubuntu prebuilt so file
initial import, CVE-2016-4117 OSX exploit
Fix bpf_priv_esc module
add DEBUG exploit binary
remove debug logging from the kernel exploit
binary drops work!
Update AF_PACKET chocobo_root Privilege Escalation module
move sploit.c out to data folder
add poc
add exploit binary
Add xplico remote code execution
Resolve a bug in reverse_tcp and segfaults across payloads
Rename payloads with os+libc, shrink array inits
Quick Ghostscript module based on the public PoC
Remove duplicated files
reduced file size
add xml erb file
move int64.js and utils.js to javascript_utils folder
add binary
add binaries
Add rds_atomic_free_op_null_pointer_deref_priv_esc (CVE-2018-5333)
addressed suggestions
Inject Payload to Memory First
Add cve-2018-8453 exploit module
Cleanup for foxit_reader_uaf
Recompile DLL and alter vcxproj file to automatically place generated DLL in right folder
move source to external/source directory
Implement on_request_uri
Update CVE-2019-13272 pre-compiled exploit
Recompile the exploit.dll DLL for CVE-2019-1458 as per Rapid7 policies
Initial commit of CVE-2019-2215 Android Binder Use-After-Free
Last additions and improvements
Add CVE-2019-8565 OSX Feedback Assistant local root exploit
@LoadLow Marks the generated ODT file readonly
Recompile everything so we don't have the messagebox calls
Add the x64 LPE exploit for CVE-2020-0796
Update binaries
Add dll
Cleanup and edits per review from Christophe Removed unused method from ps script Cleaned up some code in the module Added removal instructions to the documentation
Make second round of review edits to fix Spencer's comments
add PoC
use 2021 helper name in objective-c code too
add poc code
Add CVE-2020-7457 exploit.c
Recompiled binary exploit file to match source
add exploit binaries
Add targeting for Windows 10 v21H1
Add CVE-2021-22204 ExifTool ANT perl injection
Add PoC for CVE-2021-22555 Netfilter Priv Escalation
Tested on various other Fedora's
Add support for aarch64 Ubuntu versions
add in a build of the gadget for 12.2.1.4.0, needed as the serialVersionUID changes for classes in the coherence.jar file
Update the Python exploit code to fix a bug
Remove unneeded files
Remove the Not_Hosted target
Make adjustments to dllmain.c from reviews and recompile the DLL again
First "working" 2021-44228 exploit module state
add binaries for pre-compiled option
Rapid7 compiled binary
Initial commit of CVE-2023-43654
One exploit for CVE-2021-1732 and CVE-2022-21882
Updated pre_compiled binary
commit and sign binary
Update data to fix more things found during review process
Add rtf support to cve-2022-30190 AKA Follina
Updates to the C source code (execl instead of execve, removal of some old comments)
Rubocop
Update binary
Add exploit for CVE-2023-21768
Slight efficiency improvements
Removed unnecessary files in zip backup
Responded to comments, improved stability
vmware aria ssh keys exploit
Add error checking and randomize the report directory
Responded to comments from jvoisin
Responded to comments
osx priv-esc cve-2024-27822
Add documentation and some updates
Rebase and squash for CVE-2024-30085
Removed memory polling
Windows Access Mode Mismatch LPE in ks.sys [CVE-2024-35250]
needrestart exploit updates
code review changes from smcintyre-r7@
Add Vvveb CMS Authenticated RCE (CVE-2025-8518)
Fix bug
migrate theme licence into root directory
Remove copyfail files from dirtyfrag branch
Add Flowise CSV Agent Prompt Injection RCE module
Makes precompiled exploits static
Updates check method, updates exploits to be static-compiled
Add missing stream.raw for hp_sitescope_dns_tool
Add files via upload
burp extension all working
Add LPE exploit module for the capcom driver flaw
File.exists? must die
review touchups
Add Reliable Datagram Sockets (RDS) Privilege Escalation
Allows for Loot and Tasks to be imported from an MSF ZIP. This should bring any loots and tasks along with everything else when doing an improt from an MSF ZIP file.
Use @iZsh's exploit
fixing bperry comments
Added new module for cve-2012-5076
Added module for CVE-2012-5088
Small fix to interface
cve and references available
added security level bypass
Use signed binary
Add module for CVE-2013-1488
Added module for CVE-2013-1493
Make fixes proposed by review and clean
ppr_flatten_rec update, RDI submodule, and refactor
Add binary compiled on vs2013
Use msf branded djvu
Use cross-compiled exploit
Add ABRT raceabrt Privilege Escalation module
Add sosreport-rhel7.py
refactor ms16-016 code
add exploit for cve-2016-0189
CVE-2016-6415 Cisco - sendpacket.raw
Fix ufo_privilege_escalation
Add in compiled version of the exploit to meet Rapid7 compliance guidelines on having Rapid7 employees submit compiled binaries only
Recompile pre-compiled exploit executable (stripped, no DEBUG)
recompile binaries
chore: remove repetitive words
Add musl-cross cross-compiled executables
Combine the modules and update the binaries
Randomize container name
Working through mountpoint issues
First attempt at CVE-2020-1313
Update exploit code to use & after the command to execute as root so it executes in the background and doesn't hang Metasploit. Also update the logic of the code to check the response from executing the exploit and respond accordingly and update the documentation to match
Update c source with argc check and CRASH notes for module
First attempt at CVE-2023-34634
Pulled offsets out of dll into module. Auto-find lsass.exe when pid is 0
Data files moved. Updated to use Rex::zip and Msf::Exploit::FILEFORMAT
Adding DLL's
Call CollectGarbage
emacs extension persistence
initial commit of finished product
Add Ghostscript failed restore exploit
First attempt at CVE-2020-7200 module, with RuboCopped module
Add PS template
joplin.js.template
Added module for Java 7u17 sandboxy bypass
build: recompile dlls
Native LDAP infrastructure to support log4shell
additional code review improvements for xnode auxiliary modules/lib/docs
updated windows udf files and documentation
Use RDL
Update office_word_macro exploit to support template injection
Adjust files to be better shared
Completed version of openoffice_document_macro
Add auto-accept to osx/enum_keychain.
Added local copies of the static content
php_include: XXpathXX -> !INJECT!
Modifications based on suggestions by @wchen-r7
Fixes #3988. Adds a command execution module for PostgreSQL by uploading a UDF library and adding sys_exec() as a temporary function. Requires the target to be Windows, uses Bernardo Damele A. G.'s binaries.
fix ssl connection on Windows Server 2012
Fix enumerating emails via ProxyShell
Fixes modules to now correctly use a hash with report note
Adds scriptjunkie's multilingual admin fie for pxexploit
fix a typo with the use of CVE-2025-55102, it should be CVE-2025-55182
Add doc and enhance the module.
Add Libuser roothelper Privilege Escalation exploit
Recompile binaries and prep for VS2013 compiles
Initial working scripthost bypass uac
Cleanup of #1062
Addressed comments
Move tpwn source to external/source/exploits
Add Uso dll
Add some common UXSS scripts.
vim plugin
Quick update to make the backdoor a bit stealthier by removing the extra Payload Success! message that wasn't needed
vscode extension, untested
Permission change, ignore
Consolidation of the Axis2 Deployer Exploits Fixes #5276
Added Crash file for CVE-2010-3275 (VLC AMV file)
Added swf trigger file
Permissions fix
Permissions fix for exploit jar file
Permisssions (ignore)
Better handle of module cache when db_connect is run manually
Fix CVE-2013-2171 with @jlee-r7 feedback
add module binary
Implemented Recommended Changes
add binary for futex_requeue
Initial commit, works on three OSes, but automatic mode fails.
MS14-017 Word RTF listoverridecount memory corruption
Fix rtf info author
improve windows_defender_js_hta : -add platform detection for jsc -prevent cmd prompt when launching jsc
added build exec_payload.msi
Permissions fix for modicon_ladder.apx
Add source code to the player
Test out new player code
Moved PPSX to data/exploits folder
rename the xml template for s4u
fix chmod 644