• News/
  • https://www.bleepingcomputer.com/news/security/windows-11-and-red-hat-linux-virtualbox-hacked-on-first-day-of-pwn2own/

Windows 11 and Red Hat Linux hacked on first day of Pwn2Own

BleepingComputer
·
Sergiu Gatlan
·
Published May 15, 2025
·
Updated

On the first day of Pwn2Own Berlin 2025, security researchers were awarded $260,000 after successfully demonstrating zero-day exploits for Windows 11, Red Hat Linux, and Oracle VirtualBox. Red Hat Enterprise Linux for Workstations was the first to fall in the local privilege escalation category after DEVCORE Research Team's Pumpkin exploited an integer overflow vulnerability to earn $20,000. Hyunwoo Kim and Wongi Lee also got root on a Red Hat Linux device by chaining a use-after-free and an information leak, but one of the exploited flaws was an N-day, which led to a bug collision. Next, Chen Le Qi of STARLabs SG was awarded $30,000 for an exploit chain combining a use-after-free and an integer overflow to escalate privileges to SYSTEM on a Windows 11 system. Windows 11 was hacked twice more to gain SYSTEM privileges by Marcin Wiązowski, who exploited an out-of-bounds write vulnerability, and Hyeonjin Choi, who demoed a type confusion zero-day. Team Prison Break earned $40,000 after demoing an exploit chain that used an integer overflow to escape Oracle VirtualBox and execute code on the underlying operating system. Summoning Team's Sina Kheirkhah was awarded another $35,000 for a Chroma zero-day and an already known vulnerability in Nvidia's Triton Inference Server, while STARLabs SG's Billy and Ramdhan earned $60,000 for escaping Docker Desktop and executing code on the underlying OS using a use-after-free zero-day. ​​The Pwn2Own Berlin 2025 hacking competition, which foc...

Read full article

Affected Software

10 affected components
Microsoft Windows=11
Red Hat Enterprise Linux for Workstations
Oracle VirtualBox
Google Chroma
Nvidia Triton Inference Server
Docker Desktop
Microsoft Windows=11
Red Hat Enterprise Linux for Workstations
Red Hat Linux
Oracle VirtualBox
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the main event discussed in the article?

The article discusses the Pwn2Own Berlin 2025 event where security researchers demonstrated successful zero-day exploits.

2

Which operating systems were compromised during the event?

Windows 11 and Red Hat Linux were successfully hacked on the first day of Pwn2Own.

3

What financial rewards were given to the researchers?

Researchers were awarded a total of $260,000 for their successful exploits.

4

What virtualization software was also affected by the exploits?

Oracle VirtualBox was demonstrated to be compromised by the security researchers.

5

What are the key security implications of these exploits?

The successful hacks highlight vulnerabilities in widely-used operating systems and virtualization software, emphasizing the need for enhanced security measures.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Windows 11 and Red Hat Linux hacked on first day of Pwn2Own - SecAlerts