Rhino Security Labs

Strategic & Technical Blog

CVE-2022-25372:
Local Privilege Escalation in Pritunl VPN Client

David Yesland

The Pritunl VPN Client service is vulnerable to an arbitrary file write as SYSTEM on Windows. This is due to insecure directory permissions on the Pritunl ProgramData folder. The arbitrary file write is then able to be leveraged for full…

Java Deserialization Exploitation With
Customized Ysoserial Payloads

Fuzzing Left4Dead 2 with CERT’s
Basic Fuzzing Framework

Weaponizing AWS ECS Task Definitions
to Steal Credentials From Running Containers

Nick Spagnola

Using containers to host applications in cloud environments is an increasingly popular deployment model in AWS. Due to this trend, researchers at Rhino Security Labs explored how these containers can be abused to steal information or…