Security News > 2023 > March > Windows 11, Tesla, Ubuntu, and macOS hacked at Pwn2Own 2023

Windows 11, Tesla, Ubuntu, and macOS hacked at Pwn2Own 2023
2023-03-22 23:53

On the first day of Pwn2Own Vancouver 2023, security researchers successfully demoed Tesla Model 3, Windows 11, and macOS zero-day exploits and exploit chains to win $375,000 and a Tesla Model 3.

The STAR Labs team demoed a zero-day exploit chain targeting Microsoft's SharePoint team collaboration platform that brought them a $100,000 reward and successfully hacked Ubuntu Desktop with a previously known exploit for $15,000.

Synacktiv took home $100,000 and a Tesla Model 3 after successfully executing a TOCTOU attack against the Tesla - Gateway in the Automotive category.

Last but not least, Marcin Wiązowski elevated privileges on Windows 11 using an improper input validation zero-day that came with a $30,000 prize.

On the second day, Pwn2Own competitors will demo zero-day exploits targeting Microsoft Teams, Oracle VirtualBox, the Tesla Model 3 Infotainment Unconfined Root, and Ubuntu Desktop.

During last year's Vancouver Pwn2Own contest, security researchers earned $1,155,000 after hacking Windows 11 six times, Ubuntu Desktop four times, and successfully demonstrating three Microsoft Teams zero-days.


News URL

https://www.bleepingcomputer.com/news/security/windows-11-tesla-ubuntu-and-macos-hacked-at-pwn2own-2023/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Ubuntu 14 13 39 18 19 89
Tesla 6 3 5 1 0 9