Exploit catalog results

Showing 25 PoCs on this page

Metasploit

Windows Silent Process Exit Persistence

Metasploit exploitby Mithun ShanbhagAdded to Metasploit 2025-09-23
ExploitUnlinked1 file

exploit_windows/persistence/image_exec_options · Ruby

Analysisdeepseek-v4-pro:cloud ·

Technical assessment

This Metasploit module establishes persistence on a Windows system by uploading a payload and configuring the Silent Process Exit mechanism. It sets registry keys under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options and SilentProcessExit to trigger the uploaded payload when a specified process exits.

Backdoor review

No backdoor observed in reviewed code

The module implements a documented Windows persistence technique (Silent Process Exit) by uploading a Metasploit-generated payload and setting registry keys to execute it when a specified process exits. No concealed, deceptive, or operator-directed harmful behavior beyond the stated persistence mechanism was observed in the reviewed source code.

ClassificationExploit
Model confidence95%
AuthenticationRequired
Languagesruby
Target softwareMicrosoft Windows
Attack typespersistenceevent-triggered-execution
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The module uploads a generated payload and modifies system registry keys to execute it when a target process exits, which constitutes exploitation for persistence. It is classified as an exploit because it actively deploys and triggers malicious code on the target system.

modules/exploits/windows/persistence/image_exec_options.rb:78-82modules/exploits/windows/persistence/image_exec_options.rb:97-121

Requirements

  • Requires SYSTEM-level privileges on the target Windows host.modules/exploits/windows/persistence/image_exec_options.rb:73
  • Requires an existing Meterpreter or shell session on the target.modules/exploits/windows/persistence/image_exec_options.rb:34
  • Requires a writable directory on the target to store the payload.modules/exploits/windows/persistence/image_exec_options.rb:71

Observed behavior

  • Generates a payload executable and uploads it to a writable directory on the target.modules/exploits/windows/persistence/image_exec_options.rb:78-82
  • Creates and sets registry values under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<image_file> and SilentProcessExit\<image_file> to configure the payload as a debugger/monitor process for the specified image file.modules/exploits/windows/persistence/image_exec_options.rb:97-121
  • Records cleanup commands to delete the uploaded payload and registry keys.modules/exploits/windows/persistence/image_exec_options.rb:132-135
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

Persistence Mechanism
Payload withheldThis is the documented purpose of the module and matches the description provided in the metadata.modules/exploits/windows/persistence/image_exec_options.rb:97-121
Payload Upload
Payload withheldThis is standard behavior for a Metasploit persistence module and is necessary for the stated functionality.modules/exploits/windows/persistence/image_exec_options.rb:78-82
Cleanup Commands
Payload withheldProvides a mechanism for removing the persistence, which is consistent with a legitimate administrative tool and not indicative of a backdoor.modules/exploits/windows/persistence/image_exec_options.rb:132-135
Review boundaries

What the analysis did not establish

  • Analysis is based solely on the module source code and metadata; framework mixins, libraries, and external payloads are not expanded.
  • The evidence does not include runtime behavior, target interaction, or verification of successful exploitation.
  • The review is limited to the module source code. The behavior of the generated payload (generate_payload_exe) and the Metasploit framework mixins (e.g., Msf::Post::Windows::Registry) is not included in the evidence and was not analyzed.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.

Metasploit

Windows Cloud File Mini Filer Driver Heap Overflow

Metasploit exploitby Alex Birnberg, plus 1 additional contributorAdded to Metasploit 2025-03-20
Not analyzedCVE-2024-300851 file

exploit_windows/local/cve_2024_30085_cloud_files · Ruby

Metasploit

GameOver(lay) Privilege Escalation and Container Escape

Metasploit exploitby g1vi, plus 2 additional contributorsAdded to Metasploit 2024-11-18
Not analyzedCVE-2023-2640CVE-2023-326291 file

exploit_linux/local/gameoverlay_privesc · Ruby

Metasploit

Kemp LoadMaster Local sudo privilege escalation

Metasploit exploitby Dave Yesland with Rhino Security LabsAdded to Metasploit 2024-04-29
Not analyzedCVE-2024-12121 file

exploit_linux/local/progress_kemp_loadmaster_sudo_privesc_2024 · Ruby

Metasploit

BoidCMS Command Injection

Metasploit exploitby 1337kidAdded to Metasploit 2024-02-12
Not analyzedCVE-2023-388361 file

exploit_multi/http/cve_2023_38836_boidcms · Ruby

Metasploit

Themebleed- Windows 11 Themes Arbitrary Code Execution CVE-2023-38146

Metasploit exploitby Spencer McIntyre, plus 1 additional contributorAdded to Metasploit 2023-12-12
Not analyzedCVE-2023-381461 file

exploit_windows/fileformat/theme_dll_hijack_cve_2023_38146 · Ruby

Metasploit

Microsoft Error Reporting Local Privilege Elevation Vulnerability

Metasploit exploitby Filip Dragović (Wh04m1001), plus 1 additional contributorAdded to Metasploit 2023-09-19
Not analyzedCVE-2023-368741 file

exploit_windows/local/win_error_cve_2023_36874 · Ruby

Metasploit

Greenshot .NET Deserialization Fileformat Exploit

Metasploit exploitby p4r4bellumAdded to Metasploit 2023-08-03
Not analyzedCVE-2023-346341 file

exploit_windows/fileformat/greenshot_deserialize_cve_2023_34634 · Ruby

Metasploit

MOVEit SQL Injection vulnerability

Metasploit exploitby rbowes-r7, plus 1 additional contributorAdded to Metasploit 2023-06-14
Not analyzedCVE-2023-343621 file

exploit_windows/http/moveit_cve_2023_34362 · Ruby

Metasploit

GLPI htmLawed php command injection

Metasploit exploitby cosad3sAdded to Metasploit 2022-10-19
Not analyzedCVE-2022-359141 file

exploit_linux/http/glpi_htmlawed_php_injection · Ruby

Metasploit

Microsoft Office Word MSDTJS

Metasploit exploitby mekhalleh (RAMELLA Sébastien), plus 1 additional contributorAdded to Metasploit 2022-05-30
Not analyzedCVE-2022-301901 file

exploit_windows/fileformat/word_msdtjs_rce · Ruby

Metasploit

Watch Queue Out of Bounds Write

Metasploit exploitby Jann Horn, plus 1 additional contributorAdded to Metasploit 2022-04-06
Not analyzedCVE-2022-09951 file

exploit_linux/local/cve_2022_0995_watch_queue · Ruby

Metasploit

Local Privilege Escalation in polkits pkexec

Metasploit exploitby Andris Raugulis, plus 2 additional contributorsAdded to Metasploit 2022-01-26
Not analyzedCVE-2021-40341 file

exploit_linux/local/cve_2021_4034_pwnkit_lpe_pkexec · Ruby

Metasploit

2021 Ubuntu Overlayfs LPE

Metasploit exploitby ssd-disclosureAdded to Metasploit 2021-12-01
Not analyzedCVE-2021-34931 file

exploit_linux/local/cve_2021_3493_overlayfs · Ruby

Metasploit

ForgeRock / OpenAM Jato Java Deserialization

Metasploit exploitby Michael Stepankin, plus 2 additional contributorsAdded to Metasploit 2021-07-02
Not analyzedCVE-2021-354641 file

exploit_multi/http/cve_2021_35464_forgerock_openam · Ruby

Metasploit

Windows Privilege Escalation via TokenMagic (UAC Bypass)

Metasploit exploitby James Forshaw, plus 2 additional contributorsAdded to Metasploit 2021-05-14
Not analyzedUnlinked1 file

exploit_windows/local/tokenmagic · Ruby

Metasploit

Sudo Heap-Based Buffer Overflow

Metasploit exploitby Alexander Krog, plus 5 additional contributorsAdded to Metasploit 2021-02-04
Not analyzedCVE-2021-31561 file

exploit_linux/local/sudo_baron_samedit · Ruby

Metasploit

Microsoft Spooler Local Privilege Elevation Vulnerability

Metasploit exploitby 404death, plus 3 additional contributorsAdded to Metasploit 2020-11-20
Not analyzedCVE-2020-13371 file

exploit_windows/local/cve_2020_1337_printerdemon · Ruby

Metasploit

Windows Update Orchestrator unchecked ScheduleWork call

Metasploit exploitby Imre RadAdded to Metasploit 2020-09-18
Not analyzedCVE-2020-13131 file

exploit_windows/local/cve_2020_1313_system_orchestrator · Ruby

Metasploit

Microsoft Spooler Local Privilege Elevation Vulnerability

Metasploit exploitby Alex Ionescu, plus 2 additional contributorsAdded to Metasploit 2020-09-16
Not analyzedCVE-2020-10481 file

exploit_windows/local/cve_2020_1048_printerdemon · Ruby

Metasploit

Docker-Credential-Wincred.exe Privilege Escalation

Metasploit exploitby Morgan RomanAdded to Metasploit 2020-04-15
Not analyzedCVE-2019-157521 file

exploit_windows/local/docker_credential_wincred · Ruby

Metasploit

Service Tracing Privilege Elevation Vulnerability

Metasploit exploitby itm4nAdded to Metasploit 2020-02-27
Not analyzedCVE-2020-06681 file

exploit_windows/local/cve_2020_0668_service_tracing · Ruby

Metasploit

Microsoft UPnP Local Privilege Elevation Vulnerability

Metasploit exploitby NCC Group, plus 1 additional contributorAdded to Metasploit 2019-12-10
Not analyzedCVE-2019-1322CVE-2019-14051 file

exploit_windows/local/comahawk · Ruby

Metasploit

Windows Escalate UAC Protection Bypass (Via dot net profiler)

Metasploit exploitby "Stefan Kanthak" <stefan.kanthak () nexgo de>, plus 1 additional contributorAdded to Metasploit 2019-10-31
Not analyzedUnlinked1 file

exploit_windows/local/bypassuac_dotnet_profiler · Ruby

Metasploit

Windows Escalate UAC Protection Bypass (Via Shell Open Registry Key)

Metasploit exploitby enigma0x3Added to Metasploit 2019-10-25
Not analyzedUnlinked1 file

exploit_windows/local/bypassuac_sdclt · Ruby