Protect mission-critical assets from identity compromise with new Privilege Zones in BloodHound Enterprise. Learn More

  • Blog
  • Support
  • Contact Us
    • Blog
    • Support
    • Contact Us
  • Services
    • PROGRAM DEVELOPMENT
      • Overview
      • Developing Capabilities
      • Expert Support
    • Assessments
      • Penetration Testing
      • Red Team Engagements
      • Purple Team Assessments
      • Maturity Assessments
      • AD Attack Path Assessments
      • Artificial Intelligence Red Team
  • Products
    • BLOODHOUND
      • BloodHound
        Community Edition
        • Overview
        • BloodHound Feature Comparisons
        • GitHub
        • Get Started
      • BloodHound
        Enterprise
        • Overview
          • What is Attack Path Management?
          • Interactive Demos
          • BloodHound Feature Comparisons
          • Privilege Zones
        • Use Cases
          • Privileged Access Governance and Compliance
          • Scaling Beyond BloodHound Community Edition
          • Eliminate Lateral Movement
          • Manage Identity Risk
          • Mergers and Acquisitions
        • Industry
          • Public Sector
          • Financial Services
          • Healthcare
        • Support
        • Get a Demo
    • Go to Slack
    • Go to Docs
  • Training
    • Adversary Tactics Training Courses
      • Red Team Operations
      • Identity-Driven Offensive Tradecraft
      • Tradecraft Analysis
      • Detection
      • Vulnerability Research for Operators
      • Active Directory Security Fundamentals
      • Adversary Perspectives: Azure
    • Private Training
      • Talk to us
  • Partners
    • SpecterOps
      Partner Program
    • Identify your customers attack paths
      before attackers do
      • Become a Partner
      • Partner Portal Sign In
  • About
    • ABOUT US
      • Who We Are
      • Values
      • Team
      • Careers
      • Contact Us
  • News
    • Announcements
    • Newsroom
  • Resources
    • RESOURCES
      • Blog
      • Research & Insights
      • White Papers
      • Case Studies
      • Sponsored Tools
      • Vulnerability Acknowledgements
      • Datasheets
  • Events
    • Sponsored Events
    • Talks
    • Training Courses
    • Webinars
    • Meet Ups
Get a Demo
Get a Demo
< Back to Blog
Default Author Image

Matt Nelson

See the latest by Matt Nelson

Image for post titled CVE-2023–4632: Local Privilege Escalation in Lenovo System Updater

CVE-2023–4632: Local Privilege Escalation in Lenovo System Updater

Version: Lenovo Updater Version <= 5.08.01.0009 Operating System Tested On: Windows 10 22H2 (x64) Vulnerability: Lenovo...

By: Matt Nelson
Oct 26, 2023 • 5 min read
Read Post
Image for post titled CVE-2019–12757: Local Privilege Escalation in Symantec Endpoint Protection

CVE-2019–12757: Local Privilege Escalation in Symantec Endpoint Protection

By: Matt Nelson
Nov 15, 2019 • 5 min read
Read Post
Image for post titled Avira Optimizer Local Privilege Escalation

Avira Optimizer Local Privilege Escalation

By: Matt Nelson
Aug 17, 2019 • 8 min read
Read Post
Image for post titled CVE-2019–13382: Local Privilege Escalation in SnagIt

CVE-2019–13382: Local Privilege Escalation in SnagIt

By: Matt Nelson
Jul 24, 2019 • 9 min read
Read Post
Image for post titled CVE-2019–13142: Razer Surround 1.1.63.0 EoP

CVE-2019–13142: Razer Surround 1.1.63.0 EoP

By: Matt Nelson
Jul 5, 2019 • 5 min read
Read Post
Image for post titled Razer Synapse 3 Elevation of Privilege

Razer Synapse 3 Elevation of Privilege

By: Matt Nelson
Jan 21, 2019 • 9 min read
Read Post
Image for post titled CVE-2018–8414: A Case Study in Responsible Disclosure

CVE-2018–8414: A Case Study in Responsible Disclosure

By: Matt Nelson
Oct 18, 2018 • 4 min read
Read Post
Image for post titled The Tale of SettingContent-ms Files

The Tale of SettingContent-ms Files

By: Matt Nelson
Jun 11, 2018 • 10 min read
Read Post
Image for post titled Reviving DDE: Using OneNote and Excel for Code Execution

Reviving DDE: Using OneNote and Excel for Code Execution

By: Matt Nelson
Apr 18, 2018 • 7 min read
Read Post
1 2 3 Next
Demystifying Adversary Tradecraft
Sign Up For Updates From SpecterOps
  • Sign Up For Updates From SpecterOps

  • This field is for validation purposes and should be left unchanged.

  • Services
    • Program Development
      • Developing Capabilities
      • Expert Support
    • Assessments
      • Penetration Testing
      • Red Team Engagements
      • Purple Team Assessments
      • Maturity Assessments
      • AD Attack Path Assessment
      • Artificial Intelligence Red Team
  • Products
    • BloodHound Community Edition
      • Overview
        • BloodHound Feature Comparison
      • GitHub
      • Get Started
    • BloodHound Enterprise
      • Overview
        • What is Attack Path Management?
        • Interactive Demos
        • BloodHound Feature Comparison
      • Use Cases
        • Privileged Access Governance and Compliance
        • Scaling Beyond BloodHound Community Edition
        • Eliminate Lateral Movement
        • Manage Identity Risk
        • Mergers and Acquisitions
      • Industry
        • Public Sector
        • Financial Services
        • Healthcare
      • Support
      • Get a Demo
  • Training
    • Adversary Tactics Training Courses
      • Red Team Operations
      • Identity-Driven Offensive Tradecraft
      • Tradecraft Analysis
      • Detection
      • Vulnerability Research for Operators
      • Active Directory Security Fundamentals
      • Adversary Perspectives: Azure
      • Private Training
  • News
    • Announcements
    • Newsroom
  • About Us
    • Who We Are
    • Values
    • Team
    • Careers
    • Contact Us
  • Resources
    • White Papers
    • Case Studies
    • Sponsored Tools
    • Vulnerability Acknowledgements
    • Datasheets
  • Blog
  • Events
    • Sponsored Events
    • Talks
    • Training Courses
    • Webinars
    • Meet Ups
Great Place to Work

Copyright 2025 Specter Ops, Inc. All Rights Reserved.

Terms of Service Privacy Policy Trust Center