Wednesday, November 27, 2024
HomeHacksUbuntu Desktop & Windows 11 Hacked - Pwn2Own Day 3

Ubuntu Desktop & Windows 11 Hacked – Pwn2Own Day 3

Published on

After the first and second day, on day 3 , Three more zero-day exploits were successfully used by security researchers to hack the Windows 11 OS of Microsoft on the third and last day of the 2022 Pwn2Own Vancouver hacking contest.

Team DoubleDragon’s first attempt of the day to exploit Microsoft Teams failed because they were unable to demonstrate their exploit within the time allowed by Microsoft.

Although all is not lost, because ZDI was able to incorporate Team Double Dragon’s research into standard procedures.

- Advertisement - SIEM as a Service

The other contestants had successfully taken down Windows 11 for three times and Ubuntu Desktop for one time as well, earning them $160,000.

It was shown successfully that nghiadt12 from Viettel Cyber Security was able to exploit an integer overflow vulnerability in Windows 11 in order to gain elevated privileges.

In turn, they received a reward of $40,000 along with 4 Master of Pwn points as a reward for their execution.

On Ubuntu Desktop, a Use-After-Free exploit was successfully demonstrated by the STAR Labs’ Billy Jheng Bing-Jhong (@st424204). His mastery of Pwn capabilities earned him another $40,000 along with four more Master points.

Through an improperly implemented access control mechanism on Microsoft Windows 11, vinhthp1712 has achieved Elevation of Privilege. It has been confirmed that vinhthp1712 has been awarded $40,000 and 4 Master of Pwn points.

Bruno PUJOS from REverse Tactics has achieved Elevation of Privilege by utilizing the Use-After-Free exploit on Microsoft Windows 11 during the final attempt of the competition.

While it is also worth mentioning that this earned him $40,000 in addition to 4 Master of Pwn points.

In conclusion, the regularly scheduled programming event, Pwn2Own has concluded with this final session.

The total number of attempts this year was 21 from 17 different contestants with Trend Micro and ZDI awarding $1,155,000 to the winner.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Junior School Student Indicted for Infecting Computers With Malware

Fukui Prefectural Police have indicted a 15-year-old junior high school student from Saitama Prefecture...

Critical Gitlab Vulnerability Let Attackers Escalate Privileges

GitLab, a widely used platform for DevOps lifecycle management, has released critical security updates...

Firefox 133.0 Released with Multiple Security Updates – What’s New!

Mozilla has officially launched Firefox 133.0, offering enhanced features, significant performance improvements, and critical...

RomCom Hackers Exploits Windows & Firefox Zero-Day in Advanced Cyberattacks

In a new wave of cyberattacks, the Russia-aligned hacking group "RomCom" has been found...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Telegram Bot Selling Phishing Tools to Bypass 2FA & Hack Microsoft 365 Accounts

A newly discovered phishing marketplace, ONNX Store, empowers cybercriminals to launch sophisticated attacks against...

Mobile Device Management Vendor Mobile Guardian Hacked

 Mobile Guardian, a leading Mobile Device Management (MDM) vendor, experienced unauthorized access to its...

Hunt3r Kill3rs Group claims they Infiltrated Schneider Electric Systems in Germany

The notorious cybercriminal group Hunt3r Kill3rs has claimed responsibility for infiltrating Schneider Electric's systems...