Monday, January 27, 2025
HomeHacksUbuntu Desktop & Windows 11 Hacked - Pwn2Own Day 3

Ubuntu Desktop & Windows 11 Hacked – Pwn2Own Day 3

Published on

SIEM as a Service

Follow Us on Google News

After the first and second day, on day 3 , Three more zero-day exploits were successfully used by security researchers to hack the Windows 11 OS of Microsoft on the third and last day of the 2022 Pwn2Own Vancouver hacking contest.

Team DoubleDragon’s first attempt of the day to exploit Microsoft Teams failed because they were unable to demonstrate their exploit within the time allowed by Microsoft.

Although all is not lost, because ZDI was able to incorporate Team Double Dragon’s research into standard procedures.

The other contestants had successfully taken down Windows 11 for three times and Ubuntu Desktop for one time as well, earning them $160,000.

It was shown successfully that nghiadt12 from Viettel Cyber Security was able to exploit an integer overflow vulnerability in Windows 11 in order to gain elevated privileges.

In turn, they received a reward of $40,000 along with 4 Master of Pwn points as a reward for their execution.

On Ubuntu Desktop, a Use-After-Free exploit was successfully demonstrated by the STAR Labs’ Billy Jheng Bing-Jhong (@st424204). His mastery of Pwn capabilities earned him another $40,000 along with four more Master points.

Through an improperly implemented access control mechanism on Microsoft Windows 11, vinhthp1712 has achieved Elevation of Privilege. It has been confirmed that vinhthp1712 has been awarded $40,000 and 4 Master of Pwn points.

Bruno PUJOS from REverse Tactics has achieved Elevation of Privilege by utilizing the Use-After-Free exploit on Microsoft Windows 11 during the final attempt of the competition.

While it is also worth mentioning that this earned him $40,000 in addition to 4 Master of Pwn points.

In conclusion, the regularly scheduled programming event, Pwn2Own has concluded with this final session.

The total number of attempts this year was 21 from 17 different contestants with Trend Micro and ZDI awarding $1,155,000 to the winner.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...

GitHub Vulnerability Exposes User Credentials via Malicious Repositories

A cybersecurity researcher recently disclosed several critical vulnerabilities affecting Git-related projects, revealing how improper...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Salt Typhoon Hacked Nine U.S. Telecoms, Tactics and Techniques Revealed

Salt Typhoon, a state-sponsored Advanced Persistent Threat (APT) group linked to the People's Republic...

APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub

The malicious Southeast Asian APT group known as OceanLotus (APT32) has been implicated in...

Casio Hacked – Servers Compromised by a Ransomware Attack

Casio Computer Co., Ltd. has confirmed a significant cybersecurity breach after its servers were...