Ausnahme gefangen: SSL certificate problem: certificate is not yet valid 📌 Pwn2Own Vancouver 2023: Zero-Day Exploits Revealed for Tesla Model 3, Windows 11, and macOS

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Pwn2Own Vancouver 2023: Zero-Day Exploits Revealed for Tesla Model 3, Windows 11, and macOS


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Pwn2Own Vancouver 2023: Zero-Day Exploits Revealed for Tesla Model 3, Windows 11, and macOS

Premium Content

Patreon
Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes

Synacktiv Strikes Gold with Tesla TOCTOU Attack and macOS Privilege Escalation

At Pwn2Own Vancouver 2023, security researchers brought their A-game, demonstrating zero-day exploits and exploit chains for some of the most popular products in enterprise applications, enterprise communications, local escalation of privilege (EoP), server, virtualization, and automotive categories. The event took place between March 22 and March 24, with contestants vying for $1,080,000 in cash and prizes, including a Tesla Model 3 car.

The first day of the contest saw Adobe Reader fall victim to a six-bug logic chain exploit chain that allowed Abdul Aziz Hariri of Haboob SA to bypass a banned API list on macOS and earn $50,000. STAR Labs targeted Microsoft’s SharePoint team collaboration platform with their zero-day exploit chain and won $100,000. They also successfully hacked Ubuntu Desktop with a previously known exploit, earning $15,000. Synacktiv won $100,000 and a Tesla Model 3 after successfully executing a TOCTOU attack against the Tesla Gateway in the Automotive category. They also managed to escalate privileges on Apple macOS and earned $40,000.

 

See Also: So you want to be a hacker?
Offensive Security, Bug Bounty Courses

Qrious Security Cracks Oracle VirtualBox with OOB Read and Buffer Overflow

Qrious Security’s Bien Pham also had his day at the event, hacking Oracle VirtualBox using an OOB Read and a stacked-based buffer overflow exploit chain, which earned him $40,000. Marcin Wiązowski hacked Windows 11 using an improper input validation zero-day, which came with a $30,000 prize.

The second day of the contest targeted Microsoft Teams, Oracle VirtualBox, the Tesla Model 3 Infotainment Unconfined Root, and Ubuntu Desktop. On the final day of the event, researchers attempted to hack Microsoft Teams, Windows 11, VMware Workstation, and Ubuntu Desktop.

Contestants Aim to Apple Safari, Mozilla, VirtualBox, and more

After the event, vendors have 90 days to create and release security fixes for all reported flaws before Trend Micro’s Zero Day Initiative publicly discloses them. Last year’s Vancouver Pwn2Own contest saw security researchers earn $1,155,000 after hacking Windows 11 six times, Ubuntu Desktop four times, and successfully demonstrating three Microsoft Teams zero-days. They also reported several zero-days in Apple Safari, Oracle Virtualbox, and Mozilla Firefox, and hacked the Tesla Model 3 Infotainment System. With Pwn2Own Vancouver 2023 raising the stakes even higher, the security community eagerly awaits next year’s event.

Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com

Source: bleepingcomputer.com

Source Link

Merch

Offensive Security & Ethical Hacking Course

Begin the learning curve of hacking now!


Information Security Solutions

Find out how Pentesting Services can help you.

The post Pwn2Own Vancouver 2023: Zero-Day Exploits Revealed for Tesla Model 3, Windows 11, and macOS first appeared on Black Hat Ethical Hacking. ...



📌 Pwn2Own Vancouver 2024: Bringing Cloud-Native/Container Security to Pwn2Own


📈 44.3 Punkte

📌 Pwn2Own Vancouver 2023 awarded $1,035,000 and a Tesla for 27 0-days


📈 42.71 Punkte

📌 Pwn2Own Vancouver 2019: Tesla, VMware, Microsoft, and More


📈 39.69 Punkte

📌 Pwn2Own Vancouver 2022 D1: MS Teams exploits received $450,000


📈 37.93 Punkte

📌 Hackers earn $1,035,000 for 27 zero-days exploited at Pwn2Own Vancouver


📈 37.62 Punkte

📌 Hackers Earned $1,035,000 for Exploiting 27 Zero-Days at Pwn2Own Vancouver


📈 37.62 Punkte

📌 Announcing Pwn2Own Vancouver for 2023


📈 34.71 Punkte

📌 Hacks at Pwn2Own Vancouver 2023


📈 34.71 Punkte

📌 Pwn2Own Vancouver 2023 - The Full Schedule


📈 34.71 Punkte

📌 CVE-2023-20869/20870: Exploiting VMware Workstation at Pwn2Own Vancouver


📈 34.71 Punkte

📌 CVE-2023-20869/20870: Exploiting VMware Workstation at Pwn2Own Vancouver


📈 34.71 Punkte

📌 Pwn2Own Vancouver 2022 - Bruno PUJOS vs Microsoft Windows 11


📈 33.55 Punkte

📌 The Pwn2Own Vancouver 2022: Trend Micro and ZDI awarded $1,155,000


📈 33.47 Punkte

📌 Pwn2Own Vancouver 2019 - The Schedule and Live Results


📈 33.47 Punkte

📌 Pwn2Own Vancouver 2019: Wrapping Up and Rolling Out


📈 33.47 Punkte

📌 Pwn2Own Returns to Vancouver for 2020


📈 31.68 Punkte

📌 Announcing Pwn2Own Vancouver 2021


📈 31.68 Punkte

📌 Pwn2Own Vancouver Returns for the 15th Anniversary of the Contest


📈 31.68 Punkte

📌 Announcing Remote Participation in Pwn2Own Vancouver


📈 31.68 Punkte

📌 Regarding Pwn2Own Vancouver


📈 31.68 Punkte

📌 Pwn2Own Vancouver 2022 - The Schedule


📈 31.68 Punkte

📌 Pwn2Own Vancouver 2022 - The Results


📈 31.68 Punkte

📌 Pwn2Own Vancouver 2022 D2


📈 31.68 Punkte

📌 Pwn2Own Vancouver 2024 - The Full Schedule


📈 31.68 Punkte

📌 Windows 11, Tesla, Ubuntu, and macOS hacked at Pwn2Own 2023


📈 30.69 Punkte

📌 Cuphead: Wird für Tesla Model 3, Model S und Model X umgesetzt


📈 28.94 Punkte

📌 Tesla: Model 3, Model S und Model X mit mehr Reichweite


📈 28.94 Punkte

📌 Tesla mit Preiserhöhung in Europa: Neue Model S, Model X, Model 3 kündigen sich an


📈 28.94 Punkte

📌 Tesla: Preiserhöhung für Model 3, Model S und Model X in Deutschland


📈 28.94 Punkte

📌 Tesla wagt sich in die Höhle des Löwen: Model 3 kommt zur Pwn2Own


📈 26.41 Punkte

📌 Hackers Hacked Tesla Model 3 in Pwn2Own


📈 26.41 Punkte

📌 Hacker-Wettbewerb Pwn2Own: Teilnehmer knacken Tesla Model 3


📈 26.41 Punkte

📌 Hacker-Wettbewerb Pwn2Own: Teilnehmer knacken Tesla Model 3


📈 26.41 Punkte

📌 Tesla Model 3 Hacked in Less Than 2 Minutes at Pwn2Own Contest


📈 26.41 Punkte

📌 Pwn2Own Contest Will Pay $900,000 For Hacks That Exploit Tesla's Model 3


📈 26.41 Punkte











matomo