HomeSecurityHackers win $317,500 on first day of Pwn2Own 2015

Hackers win $317,500 on first day of Pwn2Own 2015

hackers

Hackers won a total of $317,500 by discovering three bugs in Adobe Flash and Adobe Reader , three in the Windows OS , two in Internet Explorer and two in Mozilla Firefox , on the first day of the Pwn2Own 2015 competition, sponsored by HP's Zero Day Initiative (ZDI) and Google's Project Zero , at the CanSecWest security conference in Vancouver, Canada.

Hackers Peter, Jihui Lu, and Zeguang Zhao of Team509, and wushi of KeenTeam were awarded $60,000 for breaching flash security by exploiting a heap overflow for remote code execution, and won another $25,000 for achieving system-level code execution by exploiting a local privilege escalation in the Windows kernel via the True Type font.

Nicolas Joly exploited a use-after-free (UAF) remote code execution vulnerability and a sandbox bypass to execute arbitrary code in the Flash broker and win $30,000. The hacker was also awarded another $60,000 for exploiting Adobe Reader via a stack buffer overflow, which led to information leakage and remote code execution.

Also, hackers Peter, Jihui Lu, Wen Xu, wushi (KeenTeam) and Jun Mao (Tencent PCMgr) earned another $30,000 by targeting Adobe Reader with integer overflow and achieving pool corruption via a different TTF bug, as well as another $25,000 bonus for SYSTEM escalation.

Finally, Mariusz Mlynski knocked out Mozillavia a cross-origin vulnerability and executed a logical flaw to gain SYSTEM access on Windows. He was awarded $30,000 and $25,000 respectively.

Finally, 360VulcanTeam received $32,500 for exploiting Microsoft's 64-bit Internet Explorer 11 for medium integrity code, via an uninitialized memory vulnerability.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS