This exploit chain - first demonstrated at Pwn2Own 2017 - leverages a heap overflow in Microsoft Edge, a type confusion in the ...
From the video description
3 moments
Exploitation of a Type confusion vulnerability in win32k begins | Exploitation of the VMWare SVGA uninitialized buffer | Calc.exe executes on the hypervisor
Black Hat - Europe - 2017 Hacking conference #hacking, #hackers, #infosec, #opsec, #IT, #security.
From the video description
14 moments
Agenda | Attack Surfaces | Vm Tools | Rpc Packet Handling | Vmware Virtual Printer | Cv 2016-1784 | Vmware Workstation Graphics Components That Are Susceptible to Guest To Host Escape Attacks | 2d Frame Buffer | Fifo Memory Queue | History of the Bugs | Cloudburst | Life of a Shader | Render a Shader inside a Vmware Workstation | Live Debugging
Are virtual machines safe? In theory, a virtual machine protects us from hackers, but how true is that really? In this video we'll talk ...
From the video description
Summary
Virtual machines offer a sandbox environment, but are they truly secure? This video explores VM exploits targeting the hypervisor, demonstrating how vulnerabilities can allow attacks to breach the sandbox. The analysis focuses on a specific CVE and its exploitation, highlighting the crucial role of device interfaces.
This paper presents a case study of VMWare VM escape vulnerabilities based on the analysis of different patches released by ...
From the video description
38 chapters
Intro | Why VMWare Patch Analysis? | VMWare Workstation Attack Surfaces | VM-Tools & VMWare RPC | Guest RPC Mechanism | VM Backdoor | RPC Packet Handling in Host | Sending Custom RPC Packets From Guest to Host | RPC Bug 1: OOB in Drag and Drop | Achieving OOB Read | Achieving OOB Write | Info. Leak Using OOB Write Over RPC | Bug 3: Use After Free | VMware Virtual Printer | Triggering the Print Preview | Double Free in EMR_SMALLTEXTOUTW (CVE-2016-7082) | Patch for CVE-2016-7082 | Embedded EMFSPOOL (CVE-2016-7083) | Out of Bounds Write Vulnerability in JPEG2000 Decompression (CVE-2016-7084) | Patch for CVE-2016-7084 | More Fuzzing | VMware SVGA II Device Architecture | SVGA FIFO Commands | History of Security Bugs in FIFO Commands: Cloudburst by Kostya Kortchinsky | What Are Shaders? | Life of a Shader | Shader inside VMware Workstation | Passing Shader bytecode from guest to host via 'SVGA3D' Protocol | Shader Bytecode handling in Host | Vulnerabilities in Virtual GPU | SVGA Patch 1(Workstation 12.5.4 - 12.5.5) | Heap OOB Write | Demo: SVGA Memory Corruption | Other SVGA Issues fixed in 12.5.5 | Possible Security Issue fixed in SM1 'op_calli instruction parser in version 12.5.3? | Black Hat Sound Bytes | Other Works and Recommended Reads | Questions?
Demonstrating the vmware_host_open exploit Metasploit module first discussed during the DerbyCon 2017 presentation ...
From the video description
4 moments
VMware share is empty | Payload handlers already established | Confirming exploit module options | Code execution successful. Shell artifact could be cleaned up by the payload
THE GREAT ESCAPES OF VMWARE : A Retrospective Case Study of VMware Guest to Host Escape Vulnerabilities Slides ...
From the video description
37 chapters
Intro | Why VMWare Patch Analysis? | VMWare Workstation Attack Surfaces | VM-Tools & VMWare RPC | Guest RPC Mechanism | VM Backdoor | RPC Packet Handling in Host | Sending Custom RPC Packets From Guest to Host | Achieving OOB Read | Achieving OOB Write | Info. Leak Using OOB Write Over RPC | Bug 3: Use After Free | VMware Virtual Printer | Triggering the Print Preview | Double Free in EMR_SMALLTEXTOUTW (CVE-2016-7082) | Patch for CVE-2016-7082 | Embedded EMFSPOOL (CVE-2016-7083) | Out of Bounds Write Vulnerability in JPEG2000 Decompression (CVE-2016-7084) | Patch for CVE-2016-7084 | More Fuzzing | VMware SVGA II Device Architecture | SVGA FIFO Commands | History of Security Bugs in FIFO Commands: Cloudburst by Kostya Kortchinsky | What Are Shaders? | Life of a Shader | Shader inside VMware Workstation | Passing Shader bytecode from guest to host via 'SVGA3D' Protocol | Shader Bytecode handling in Host | Vulnerabilities in Virtual GPU | SVGA Patch 1(Workstation 12.5.4 - 12.5.5) | Demo: SVGA Memory Corruption | SM4 'dcl_constantbuffer' Instruction Parsing (Ox59) Bug | Other SVGA Issues fixed in 12.5.5 | Possible Security Issue fixed in SM1 'op_calli instruction parser in version 12.5.3? | Black Hat Sound Bytes | Other Works and Recommended Reads | Questions?