• News/
  • https://www.bleepingcomputer.com/news/security/windows-11-tesla-and-ubuntu-linux-hacked-at-pwn2own-vancouver/

Windows 11, Tesla, and Ubuntu Linux hacked at Pwn2Own Vancouver

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 21, 2024
·
Updated

On the first day of Pwn2Own Vancouver 2024, contestants demoed 19 zero-day vulnerabilities in Windows 11, Tesla, Ubuntu Linux and other devices and software to win $732,500 and a Tesla Model 3 car. The competition started with Haboob SA's Abdul Aziz Hariri using an Adobe Reader exploit that combined an API restriction bypass and a command injection bug to gain code execution on macOS to earn $50,000. Synacktiv won the Tesla Model 3 and $200,000 after hacking the Tesla ECU with Vehicle (VEH) CAN BUS Control in under 30 seconds using an integer overflow. Theori security researchers Gwangun Jung and Junoh Lee earned $130,000 after escaping a VMware Workstation VM to gain code execution as SYSTEM on the host Windows OS using a chain targeting an uninitialized variable bug, a UAF weakness, and a heap-based buffer overflow. Reverse Tactics' Bruno PUJOS and Corentin BAYET collected $90,000 by exploiting two Oracle VirtualBox bugs and a Windows UAF to escape the VM and elevate privileges to SYSTEM. The first day of the contest ended with Manfred Paul hacking the Apple Safari, Google Chrome, and Microsoft Edge web browsers, exploiting three zero-day vulnerabilities and winning $102,500.

Other attempts from the first day of Pwn2Own include: After the zero-days are demoed at Pwn2Own, vendors have 90 days to create and release security patches for all reported flaws before Trend Micro's Zero Day Initiative discloses them publicly. ​​Throughout Pwn2Own Vancouver 2024, security researche...

Read full article

Affected Software

11 affected components
Microsoft Windows =11
Canonical Ubuntu Linux
Adobe Reader
Tesla ECU
VMware Workstation
ORACLE VirtualBox
apple Safari
Google Chrome
Microsoft Edge
Mozilla Firefox
Docker Desktop
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What event did the security vulnerabilities occur at?

The vulnerabilities were demonstrated at the Pwn2Own Vancouver 2024 competition.

2

What types of products were affected by the zero-day vulnerabilities?

Affected products included Windows 11, Tesla ECU, Ubuntu Linux, and various software applications like Adobe Reader and web browsers.

3

How many vulnerabilities were successfully demonstrated during the event?

Contestants demoed 19 zero-day vulnerabilities during the competition.

4

What reward did participants compete for at Pwn2Own Vancouver?

Participants competed for a prize pool of $732,500 and a Tesla Model 3 car.

5

Which major tech companies' products were mentioned as being hacked?

The hacked products included those from Microsoft, Tesla, Canonical, Adobe, VMware, Oracle, Apple, Google, and Mozilla.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203