Security research is best when it results in stronger systems. These are vulnerabilities I have reported and acknowledgements I have received through responsible disclosure.

CVE High ยท CVSS 7.8

CVE-2022-43517

Siemens Simcenter STAR-CCM+

Improper permissions on the installation folder could allow a local, low-privileged user to replace the service executable and gain SYSTEM privileges.

Siemens credited Craig Carr of the University of Glasgow for reporting the vulnerability.

Honor Roll

SiteGround

PostgreSQL pg_shadow leak

Recognised by SiteGround for responsibly reporting a PostgreSQL pg_shadow information leak.

Listed on SiteGround's public Honor Roll.