David Carliez
Just another Freelance Offensive Security Professional. The posts in this blog are snippets of my work that can be shared publicly.
Find me on
Blog
-
Cover: Reversible Privacy for AI Coding Agents
How Cover replaces private values with deterministic fakes before an AI request, then restores the originals locally without breaking agent context.
-
CVE-2026-66804: CrossDevice Frame Server LPE
How a user-writable CrossDevice COM server path let a current-user Media Foundation virtual camera load native code through Windows Camera Frame Server.
-
CVE-2026-49176 Exploit Development: WalletService to SYSTEM
Exploit development for the Windows WalletService vulnerability, from caller-controlled known-folder resolution to a persisted ESE callback and an interactive SYSTEM shell.
-
Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
-
CVE-2026-58635 Exploit Development: From a Braille Table to SYSTEM shell
Exploit development for the Windows Narrator Braille vulnerability, from an unauthenticated BrlAPI parameter write to LocalService execution and an optional SYSTEM shell.
Research areas
-
Vulnerability research
Source-guided audits, patch diffing, advisory bypasses, and maintainer-ready proof.
-
AI agent security
CLI sandboxes, MCP/tool permissions, command execution, and browser automation boundaries.
-
Windows LPE
Local privilege escalation research, n-day validation, drivers, services, and abuse primitives.
-
Exploit tooling
Harnesses, fuzzing setups, diff scripts, and reproducible artifacts that turn bugs into proof.