Security News > 2023 > March > Microsoft Teams, Virtualbox, Tesla zero-days exploited at Pwn2Own
Competitors successfully exploited zero-day bugs in multiple products during the second day of Pwn2Own Vancouver 2023, including the Tesla Model 3, Microsoft's Teams communication platform, the Oracle VirtualBox virtualization platform, and the Ubuntu Desktop operating system.
Team Viettel hacked also Microsoft Teams via a 2-bug chain to earn $78,000 and Oracle's VirtualBox using a Use-After-Free bug and an uninitialized variable for $40,000.
On the first day, Pwn2Own competitors were awarded $375,000 and a Tesla Model 3 after successfully demoing 12 zero-days in the Tesla Model 3, Windows 11, Microsoft SharePoint, Oracle VirtualBox, and macOS. On the last day of the contest, security researchers will attempt to exploit zero-day bugs in Ubuntu Desktop, Microsoft Teams, Windows 11, and VMware Workstation.
Pwn2Own Vancouver 2023 contestants can earn $1,080,000 in cash and two Tesla Model 3 cars between March 22 and March 24.
Vendors have to patch zero-day vulnerabilities demoed and disclosed during Pwn2Own within 90 days before Trend Micro's Zero Day Initiative publicly publishes technical details.
At Pwn2Own Vancouver 2022, security researchers earned $1,155,000 after hacking the Tesla Model 3 Infotainment System, taking down Windows 11 six times, demonstrating three Microsoft Teams zero-days, and exploiting Ubuntu Desktop four times.
News URL
Related news
- Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security tools (source)
- Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws (source)
- Microsoft fixes Windows Smart App Control zero-day exploited since 2018 (source)
- Microsoft fixes 4 exploited zero-days and a code defect that nixed earlier security fixes (source)
- Patch Tuesday for September 2024: Microsoft Catches Four Zero-Day Vulnerabilities (source)
- Microsoft confirms IE bug squashed in Patch Tuesday was exploited zero-day (source)
- Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws (source)
- Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) (source)
- Hackers exploit 52 zero-days on the first day of Pwn2Own Ireland (source)
- Black Basta poses as IT support on Microsoft Teams to breach networks (source)