Validated! Dungdm (@_piers2) of Viettel Cyber Security used two bugs, include the ever risky race condition, to exploit #Oracle VirtualBox. As a round 3 winner, they receive $20,000 and 4 Master of Pwn points. #Pwn2Own#P2OVancouver
๐ ACSC 2024 (Asian Cyber Security Challenge) is Happening!๐
๐ March 30-31, 2024 ๐ Mark your calendars!
๐ Registration opening soon. Don't miss out!
More details here โถ๏ธ https://t.co/TmZFSjOgx8
#ACSC2024#CyberSecurity#SaveTheDate
@y0ny0ns0n I was first relieved when there is no cve in the released advisories. Then I self-doubt, so i update and check again. And they fixed it silently ๐
In Vmware Workstation 17.5.1, a bug was silently patched, I was going to use it for Pwn2Own but i think that I probably found the same bug that was used in TFC 2023... :(
@vv474172261, is there a way i can confirm this with you ?
Will still try to do a blog post on my @CSAW_NYUTandon CTF challenge, NERV Center, but for now here's a thread explaining the key mechanics. I put a lot of work into the aesthetics, like this easter egg credit sequence (all ANSI colors+unicode text) that contains key hints:
- Writes shitty Hypervisor fuzzer as an example for someone junior
- Runs shitty fuzzer against VirtualBox
- Finds 0-day...
It was a few hours of effort?
In an attack surface that already had a 0-day a bit ago?
Incoming blog for fun ๐
That's a wrap on #Pwn2Own Toronto 2023! We awarded $1,038,250 for 58 unique 0-days during the event. Congratulations to Team Viettel (@vcslab) for winning Master of Pwn with $180K and 30 points. We'll see you at Pwn2Own Automotive in Tokyo next January.