Security News > 2021 > April > $200,000 Awarded for Zero-Click Zoom Exploit at Pwn2Own

$200,000 Awarded for Zero-Click Zoom Exploit at Pwn2Own
2021-04-08 11:13

Two researchers earned $200,000 on the second day of the Pwn2Own 2021 hacking competition for a Zoom exploit allowing remote code execution without user interaction.

Also on the second day of Pwn2Own 2021, Bruno Keith and Niklas Baumstark of Dataflow Security earned $100,000 for an exploit that works both on the Chrome and Microsoft Edge web browsers.

Team Viettel attempted to hack Microsoft Exchange, but their exploit leveraged a vulnerability that was used earlier in the competition so their attempt counted as a partial win.

On the first day of Pwn2Own 2021, participants earned $570,000, including $440,000 for exploits targeting Microsoft products.

According to Trend Micro's Zero Day Initiative, which organizes the competition, it's the first time more than one million dollars have been paid out in total at Pwn2Own, and there are still several more attempts scheduled for the last day of the event.

The hacking attempts scheduled for the third day of Pwn2Own will target Parallels, Exchange, Ubuntu, and Windows 10.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/9vD9IOnaspA/200000-awarded-zero-click-zoom-exploit-pwn2own

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Zoom 51 4 50 57 8 119