Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Clément Labro

@itm4n@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Pentest & Windows security research

1015 Followers
155 Following
10 Posts
Joined November 05, 2022
Blog:
https://itm4n.github.io/
GitHub:
https://github.com/itm4n
Bluesky:
https://bsky.app/profile/itm4n.bsky.social
Open post
Clément Labro @itm4n@infosec.exchange
· 6mo ago

🆕 New blog post!

"BitLocker's Little Secrets: The Undocumented FVE API"

A small Windows RE adventure to figure out how to get the status and configuration of a BitLocker protected drive programmatically and without admin privileges.

Now also implemented in PrivescCheck! 🔥

👉 https://itm4n.github.io/bitlocker-little-secrets-the-undocumented-fve-api/

itm4n’s blog

BitLocker’s Little Secrets: The Undocumented FVE API

The purpose of the BitLocker check I implemented in PrivescCheck is to determine whether the system drive is protected, and if so, whether two-factor authentication is configured (typically TPM+PIN). You’d think that it’s a simple thing to do, but it is not, at least without administrator rights.

17
2
13
0
Open post
Clément Labro @itm4n@infosec.exchange
· 6mo ago

This is my analysis (and PoC) for CVE-2026-20817, a privilege escalation in the Windows Error Reporting service.

👉 https://itm4n.github.io/cve-2026-20817-wersvc-eop/

Credit goes to Denis Faiustov and Ruslan Sayfiev for the discovery.

TL;DR A low privilege user could send an ALPC message to the WER service and coerce it to start a WerFault.exe process as SYSTEM with user-controlled arguments and options. I did not achieve arbitrary code execution, but perhaps someone knows how this can be done? 🤷‍♂️

itm4n’s blog

CVE-2026-20817 - Windows Error Reporting Service EoP

This vulnerability was such a gaping hole in the Windows Error Reporting service that Microsoft completely removed the affected feature. A low privilege user could simply send a specially crafted ALPC message with a reference to a command line that the service executed with SYSTEM privileges. At least that’s what I thought initially.

10
4
11
0
Open post
Clément Labro @itm4n@infosec.exchange
· 6mo ago

Yet another abuse of the missing "CrossDevice.Streaming.Source.dll" DLL!

After CVE-2025-24076 / CVE-2025-24076 found by Compass Security, Researcher Oscar Zanotti Campo found another vulnerability that he could exploit using the built-in misconfigured COM class referencing this DLL. This is CVE-2026-21508. 🔥

👉 https://0xc4r.github.io/posts/CVE-2026-21508/
👉 https://github.com/0xc4r/CVE-2026-21508_POC/
👉 https://blog.0patch.com/2026/03/micropatches-released-for-windows.html

#Windows #cve #cve_2026_21508 #vulnerability

0xc4r

CVE-2026-21508 - Windows Local Privilege Escalation via arbitrary COM object initialization

Windows Storage Elevation of Privilege Vulnerability

7
0
7
0
Open post
Clément Labro @itm4n@infosec.exchange
· 12mo ago

A nice and short blog post about blinding EDR with WFP by my colleague Florian.

"Blinding EDRs: A deep dive into WFP manipulation"

https://blog.scrt.ch/2025/08/25/blinding-edrs-a-deep-dive-into-wfp-manipulation/

blog.scrt.ch

Blinding EDRs: A deep dive into WFP manipulation – SCRT Team Blog

8
0
5
0
Open post
Clément Labro @itm4n@infosec.exchange
· 7mo ago

It's a blog post I should have published months ago, but here we finally are.

"CVE-2025-59201 - Network Connection Status Indicator (NCSI) EoP"

Credit goes to t0zhang (on X) for the discovery.

👉 https://itm4n.github.io/cve-2025-59201-ncsi-eop/

I'd like to write more of those but it's so time-consuming. 😔

#cve #windows

itm4n’s blog

CVE-2025-59201 - Network Connection Status Indicator (NCSI) EoP

It’s been a while since I last dug into a Patch Tuesday release. With an extraordinarily high number of 177 CVEs, including 6 that were either already public or exploited in the wild, the October 2025 one seemed like a good opportunity to get back at it. The one I ended up investigating in depth was CVE-2025-59201, an elevation of privilege in the “Network Connection Status Indicator”.

3
6
7
0
Open post
Clément Labro @itm4n@infosec.exchange
· 8mo ago

One of the best blog posts I've read recently. Complex subject but very accessible explanations. Great job by Ksawery Czapczyński a.k.a. @0xXaFF.

"PatchGuard Peekaboo: Hiding Processes on Systems with PatchGuard in 2026"

https://www.outflank.nl/blog/2026/01/07/patchguard-peekaboo-hiding-processes-on-systems-with-patchguard-in-2026/

PatchGuard Peekaboo: Hiding Processes on Systems with PatchGuard in 2026 | Outflank
Outflank

PatchGuard Peekaboo: Hiding Processes on Systems with PatchGuard in 2026 | Outflank

Documenting kernel-level process hiding techniques on Windows 11 with HVCI enabled. Journey from failed inline hooks to successful data-based bypasses.

4
0
2
0
Open post
Clément Labro @itm4n@infosec.exchange
· 6mo ago
Replying to
@CravateRouge Merci ! Si, c'est assez fastidieux en effet, mais c'est le genre de chose que je dois faire régulièrement pour PrivescCheck de toute façon. Et puis j'ai ajouté les définitions uniquement pour les types dont j'avais besoin. 😉
1
0
0
0
Open post
Clément Labro @itm4n@infosec.exchange
· 7mo ago
Replying to
@CravateRouge Hey! Merci. :) Yes, there are many interesting vulnerabilities like this that get patched each month. It's too bad they are generally not documented publicly. I have another one in store from the January 2026 Patch Tuesday. Hopefully, I'll be able to figure it out and publish a writeup as well. 🤞
0
1
0
0
Open post
Clément Labro @itm4n@infosec.exchange
· 7mo ago
Replying to
@CravateRouge Yes, I know, me neither. As I wrote an the end of the blog post, I didn't go any further than that.
0
1
0
0
Open post
Clément Labro @itm4n@infosec.exchange
· 6mo ago
Replying to
@tiraniddo@infosec.exchange Yes, it does, but the handle returned to the client only has the SYNCHRONIZE right. :/ The client has full control of the command line arguments. I thought about the COM IRundown trick indeed, but I wondered if there was something more straightforward. ^^ I don't see any reason it would not work though. One thing to note is that the process inherits the client's environment variables.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:30:47 UTC