Pwn2Own Vancouver 2024 has ended with security researchers collecting $1,132,500 after demoing 29 zero-days (and some bug collisions). Throughout the event, they targeted software and products in the web browser, cloud-native/container, virtualization, enterprise applications, server, local escalation of privilege (EoP), enterprise communications, and automotive categories, all up-to-date and in their default configuration. The total prize pool was over $1,300,000 in cash prizes and a Tesla Model 3, which Team Synacktiv won on the first day. Competitors successfully gained code execution and escalated privileges on fully patched systems after hacking Windows 11, Ubuntu Desktop, VMware Workstation, Oracle VirtualBox, three web browsers (Apple Safari, Google Chrome, and Microsoft Edge), and the Tesla Model 3. Vendors have 90 days to release security fixes for zero-day vulnerabilities reported during Pwn2Own contests before TrendMicro's Zero Day Initiative discloses them publicly. Manfred Paul won this year's edition of Pwn2Own Vancouver with 25 Master of Pwn points and $202,500 earned throughout the two-day competition after hacking the Apple Safari, Google Chrome, and Microsoft Edge web browsers. On the first day of Pwn2Own, he gained remote code execution (RCE) in Safari via an integer underflow bug and a PAC bypass zero-day combo. He then used a double-tap RCE exploit targeting an Improper Validation of Specified Quantity in Input weakness to take down Chrome and Edge. Syna...
Hackers earn $1,132,500 for 29 zero-days at Pwn2Own Vancouver
BleepingComputer
·Sergiu Gatlan
·Published Mar 22, 2024
·Updated
Affected Software
9 affected components
Microsoft Windows =11
canonical Ubuntu Desktop
VMware Workstation
ORACLE VirtualBox
apple Safari
Google Chrome
Microsoft Edge
Tesla Model 3
Mozilla Firefox
Frequently Asked Questions
1
What event is the article discussing regarding cybersecurity?
The article discusses the Pwn2Own Vancouver 2024 event where hackers demonstrated 29 zero-day vulnerabilities.
2
How much money did security researchers earn at Pwn2Own Vancouver?
Security researchers earned a total of $1,132,500 for their demonstrations of zero-days.
3
What types of software were targeted during the Pwn2Own event?
Researchers targeted various software including web browsers, cloud-native applications, and virtualization products.
4
Which specific products are mentioned as affected by the vulnerabilities?
Affected products include Microsoft Windows 11, Ubuntu Desktop, VMware Workstation, Oracle VirtualBox, Safari, Chrome, Edge, Mozilla Firefox, and Tesla Model 3.
5
What is the significance of reporting zero-day vulnerabilities at Pwn2Own?
Reporting zero-day vulnerabilities at Pwn2Own is significant because it helps improve security by allowing vendors to patch their software against these exploits.