// htb writeup HackTheBox 2026-05-24
VariaType
HackTheBox Medium HackTheBox
seasonal
root obtained // PWNED

🔤 VariaType

Difficulty: Medium OS: Linux Release: HTB Season 10

A Linux box themed around typography tooling — the whole kill chain runs through CVEs in font processing libraries. Three separate CVEs, three different users, and every step involving file handling that developers never expected to reach an attacker. If you know your way around font toolchains, the vulnerability surface here will feel very familiar.


📸 Proof

🧠 Concepts Covered


💡 Hints (No Spoilers)

Foothold

User

Root


📚 Useful Reading