Pwn2Own Berlin 2025 Reveals The Next Topics On Insecurity Corner

Source: Bleeping Computer Pwn2Own Berlin 2025 Reveals The Next Topics On Insecurity Corner

Find Stupid Bugs, Win Serous Cash

Pwn2Own has kicked off in Berlin and a disturbing number of zero days have been on display on the first day.  They range from Windows 11 to Red Hat to Oracle’s Virtualbox and may soon be coming to a computer near you unless the vulnerabilities can be patched quickly.  There were three found for Microsoft’s OS, including an integer overflow, a type confusion and an out-of-bounds write vulnerability all of which granted SYSTEM privileges to an attacker.  Red Hat failed in the local privilege escalation category thanks to another integer overflow vulnerability as well as chaining a use-after-free and information leak attack, part of which was already known but still vulnerable to exploitation.  The day also included an integer overflow bug that allows an attacker to escape Oracle VirtualBox and execute code on the underlying operating system, which is definitely a bad thing!

There were a few other exploits discovered and bounties paid for the first day covered at Bleeping Computer.  Day two will see Microsoft SharePoint, VMware ESXi, Mozilla and Firefox tested, along with more attempts at Red Hat Enterprise Linux for Workstations, and Oracle VirtualBox.  Thankfully all of these exploits will be thoroughly documented and the victims given the details so they can patch them.   Still, Pwn2Own is always stressful for the security minded.

On the first day of Pwn2Own Berlin 2025, security researchers were awarded $260,000 after successfully demonstrating zero-day exploits for Windows 11, Red Hat Linux, and Oracle VirtualBox.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!