Categories: MicrosoftWindows

Microsoft’s Windows 10, Exchange, And Teams Hacked At Pwn2Own

Microsoft’s Windows 10, Exchange, And Teams Hacked At Pwn2Own

During the first day of Pwn2Own 2021, contestants won $440,000 after successfully exploiting previously unknown vulnerabilities to hack Microsoft’s Windows 10 OS, the Exchange mail server, and the Teams communication platform.

The first to fall was Microsoft Exchange in the Server category after the Devcore team achieved remote code execution on an Exchange server by chaining together an authentication bypass and a local privilege escalation. This brought them $200,000 and 20 Master of Pwn points.

Next, a security researcher using the OV online moniker successfully obtained code execution on Microsoft Teams in the Enterprise Communications category by combining two separate security bugs. He also earned $200,000 and 20 Master of Pwn points.

Team Viettel earned $40,000 and 4 Master of Pwn points after escalating privileges to SYSTEM from a regular user on Windows 10 while competing in the Local Escalation of Privilege category.

On the first day, RET2 Systems’s Jack Dates also won $100,000 after successfully obtaining kernel-level code execution on macOS using an Apple Safari integer overflow and Out-of-bounds Write bugs.

Also Read: The DNC Registry Singapore: 5 Things You Must Know

Ryota Shiga of Flatt Security won $30,000 for an OOB access bug that allows gaining root on a Ubuntu Desktop machine.

The STAR Labs team failed to get their exploits to work in the allotted time while trying to exploit Oracle VirtualBox and Parallels Desktop in the Virtualization category.

On the second day, Pwn2Own competitors will also target Google Chrome, Microsoft Edge (Chromium), Zoom Messenger, while others will try their hand at exploiting other new bugs in Microsoft Exchange, Windows 10, Ubuntu Desktop, and Parallels Desktop.

After the vulnerabilities are exploited and disclosed during Pwn2Own, software and hardware vendors are given 90 days to develop and release security fixes for all vulnerabilities reported.

During the Pwn2Own 2021 contest, 23 teams and researchers will target ten different products in the Web Browsers, Virtualization, Servers, Local Escalation of Privilege, and Enterprise Communications categories.

Between April 6 and April 8, Pwn2Own contestants will be able to earn over $1,500,000 in cash and prizes, including a Tesla Model 3.

Team Fluoroacetate was the first to win Tesla Model 3 Pwn2Own after hacking the car’s Chromium-based infotainment system two years ago.

Also Read: How To Comply With PDPA: A Checklist For Businesses

They also earned $375,000 at Pwn2Own 2019 after demoing exploits for Apple Safari, Oracle VirtualBox, VMware Workstation, Mozilla Firefox, and Microsoft Edge.

Privacy Ninja

Recent Posts

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

2 weeks ago

Prioritizing Security Measures When Launching Webpage

Prioritizing Security Measures When Launching a Webpage That Every Organisation in Singapore should take note…

2 weeks ago

The Importance of Regularly Changing Passwords for Enhanced Online Security

Importance of Regularly Changing Passwords for Enhance Online Security that every Organisation in Singapore should…

3 weeks ago

Mitigating Human Errors in Organizations: A Comprehensive Approach to Data Protection and Operational Integrity

Comprehensive Approach to Data Protection and Operational Integrity that every Organsiation in Singapore should know…

3 weeks ago

The Importance of Pre-Launch Testing in IT Systems Implementation

Here's the importance of Pre-Launch Testing in IT Systems Implementation for Organisations in Singapore. The…

4 weeks ago

Understanding Liability in IT Vendor Relationships

Understanding Liability in IT Vendor Relationships that every Organisation in Singapore should look at. Understanding…

1 month ago