Skip to main content

Virtual machine escape fetches $105,000 at Pwn2Own hacking contest [updated]


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Hack worked by stitching together three separate exploits.

 
                                 


 
Dan Goodin - 3/17/2017
 
Contestants at this year's Pwn2Own hacking competition in Vancouver just pulled off an unusually impressive feat: they compromised Microsoft's heavily fortified Edge browser in a way that escapes a VMware Workstation virtual machine it runs in. The hack fetched a prize of $105,000, the highest awarded so far over the past three days.
 
According to a Friday morning tweet from the contest's organizers, members of Qihoo 360's security team carried out the hack by exploiting a heap overflow bug in Edge, a type confusion flaw in the Windows kernel and an uninitialized buffer vulnerability in VMware, contest organizers reported Friday morning on Twitter. The result was a "complete virtual machine escape."
 
Full Article

0 replies

Be the first to reply!

Reply