I'm a 20-year-old security researcher from the Netherlands. I find and report vulnerabilities in production systems, from kernel drivers to web applications.
Currently focused on binary exploitation, Windows kernel-level vulnerability research, and expanding my public research archive.
| Target | Type | Impact |
|---|---|---|
| dam.sys | Kernel driver bugs (x4) | BSOD + confused deputy + info leak + session freeze from standard user |
| Windows Defender | NTLM coercion | Standard user forces SYSTEM credential leak via UNC path |
| Windows Defender | Signature lock bypass | FILE_SHARE_READ locks signatures on patched systems |
| Firefox | IPC sandbox escape | Unvalidated AddCertException → silent MITM on arbitrary hostnames |
| Mosquitto | Pre-auth RCE | Empty WebSocket frame heap overwrite → code execution |
| MySQL Router | OAuth cache ATO | Display-name cache collision → account takeover (CVSS 9.1) |
| Keep | Unauth RCE | Provider invoke chain → unauthenticated remote code execution |
| OpenVPN (ovpn-dco-win) | Kernel UAF | CNG key use-after-free in kernel driver |
| Overwolf Updater | LPE to SYSTEM | Forged Authenticode cert + insecure service DACL |
| Safe Exam Browser | Auth bypass + RCE | Service auth bypass → log injection → RCE as SYSTEM |
| StorSvc | DLL hijack LPE | LoadLibraryW without LOAD_LIBRARY_SEARCH_SYSTEM32 → SYSTEM |
| Discord Desktop | RCE | Multiple desktop client RCE attack paths |
| Nextcloud | XXE + SSRF | File read/SSRF + protection bypass chain |
| Wazuh | Stack BOF + DoS | Stack buffer overflow + SCA denial of service |
| n8n | SSRF | Server-side request forgery via OAuth2 callback |
| Fluent Bit | Pre-auth DoS | collectd parser infinite loop from unauthenticated input |
| Woodpecker CI | Pipeline RCE | \r bypass of newline sanitization → YAML injection |
| spacedesk | LPE to SYSTEM | Everyone full-control service DACL |
| LibreNMS | SSTI → RCE | Template injection to remote code execution chain |
| RetroArch (libchdr) | Heap overflow | Integer overflow → OOB write on 32-bit via crafted CHD |
"You can't secure what you don't understand."
— Bruce Schneier


