Back to directory
WRITEUP #802

CVE-2023-38146: Arbitrary Code Execution via Windows Themes

RCETOCTOUDLL Hijacking
bygabe_k
Bounty
5,000
Program
Microsoft (Windows)
Published
Sep 13, 2023
Added to HackDex
Sep 19, 2023
Read Full Writeuphttps://exploits.forsale/themebleed/
RELATED WRITEUPS
KnowBe4 RCE and LPE
RCELocal Privilege Escalation
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write

Built with ❤️ by Shubham Rawat