Congratulations to our MSRC 2022 Most Valuable Researchers! Thank you to all the researchers who have helped secure our customers. Check out our blog for the full list: https://t.co/vYnm9u3xSE #cybersecurity#securityresearch
The first nomination for best RCE:
None other than @KunlunLab for CVE-2022-26809, their 20 year old (!) Windows RPC Bug.
You can read more about it here:
https://t.co/FWn19f0s58
@bugch3ck@GossiTheDog @cyberkunlun The @ symbol there means he is from cyber Kunlun company, not a twitter handler (that’s why MSRC was not hyper-linked it)
@danehrlich11 @ChineseEmbinUK@mj0011sec Kunlun lab is not a company or entity , just a name of our research team, it has nothing related to the company or register stuff. Do some homework before your bullshit.
This patch Tuesday fixed 5 vulnerabilities discovered by @KunlunLab. 2 of them were for @TianfuCup pdf reader sandbox escape & Win10 LPE, 1 CLFS bug was caught as in the wild exploit.
First patch Tuesday of 2022! Adobe and Microsoft fixed 6 vulnerabilities reported by Kunlun lab. Two of them were demoed @TianfuCup. The CVE-2021-44706 was the RCE of PDF reader full chain and the CVE-2021-21881 was the Ntoskrnl bug for Chrome sandbox escape.
Google just released Chrome 95.0.4638.69 & fixed two TianfuCup bugs which become the first patch for TianfuCup 2021 https://t.co/jCqcs3Cpll CVE-2021-38001 is the RCE from Kunlun lab & CVE-2021-38002 is the SBX from 360(RCE one silence killed)
New company but still ranked as #1 this year TianfuCup. Almost all targets are fully pwned this time(except Synology). last photo : the empty review room after 0day party
First confirmed entry for day1 of TianfuCup, Kunlun Lab @S0rryMybad pwned Google Chrome to get Windows system kernel level privilege with only two bugs. First time since 2015 as I remembered