May 19 2022

Pwn2Own Vancouver 2022 D1: MS Teams exploits received $450,000

Category: HackingDISC @ 9:52 am

White hat hackers earned a total of $800,000 on the first day of the Pwn2Own Vancouver 2022, $450,000 for exploits targeting Microsoft Teams.

Pwn2Own Vancouver 2022 hacking contest has begun, it is the 15th edition of this important event organized by Trend Micro’s Zero Day Initiative (ZDI). This year, 17 contestants are attempting to exploit 21 targets across multiple categories.

During the first day of the event, white hat hackers earned a total of $800,000, a record for the first day of this contest, including $450,000 for successful exploits targeting Microsoft Teams.

All the attempts made during the first day were successful, the participants explored a total of 16 flaws affecting Microsoft Teams, Oracle VirtualBox, Firefox, Windows 11, Ubuntu, and Safari.

Pwn2Own Vancouver 2022

Below is the list of hacking attempts against Microsoft Teams:

  • SUCCESS – Hector “p3rr0” Peralta was able to demonstrate an improper configuration against Microsoft Teams. He earns $150,000 and 15 Master of Pwn points.
  • SUCCESS – Masato Kinugawa was able to execute a 3-bug chain of injection, misconfiguraton and sandbox escape against Microsoft Teams, earning $150,000 and 15 Master of Pwn points.
  • SUCCESS – Daniel Lim Wee Soong (@daniellimws, Poh Jia Hao (@Chocologicall), Li Jiantao (@CurseRed) & Ngo Wei Lin (@Creastery of STAR Labs successfully demonstrated their zero-click exploit of 2 bugs (injection and arbitrary file write) on Microsoft Teams. They earn $150,000 and 15 Master of Pwn points.

Manfred Paul (@_manfp) successfully demonstrated the exploitation of prototype pollution and improper input validation on Mozilla Firefox. Paul earned $100,000 and 10 Master of Pwn points.

Paul also exploited an out-of-band write issue on Apple Safari and earned $50,000 and 5 additional Master of Pwn points.

The remaining exploits received a $40,000.

Windows 11 hacked again at Pwn2Own, Telsa Model 3 also falls

Pwn2Own Vancouver 2022 – Keith Yeo vs Ubuntu Desktop

Pwn2Own Vancouver 2022 – Drawing for Order

Pwn2Own Vancouver 2022 – TUTELARY vs Ubuntu Desktop

Pwn2Own Vancouver 2022 – Synacktiv vs Tesla

Tags: pwn2own, Pwn2Own Vancouver 2022

Leave a Reply

You must be logged in to post a comment. Login now.