This week we look at results from the Tianfu Cup 2020, the PLATYPUS attack
against Intel CPUs, a detailed writeup of the GDM/accountsservice
vulnerabilities covered in Episode 95 and more.
Show Notes
Overview
This week we look at results from the Tianfu Cup 2020, the PLATYPUS attack
against Intel CPUs, a detailed writeup of the GDM/accountsservice
vulnerabilities covered in Episode 95 and more.
QEMU on Ubuntu, Firefox and docker all pwned (as well as Chrome, Safari,
VMWare ESXi, CentOS 8, iPhone etc)
qemu-kvm on Ubuntu - used a UAF and an info-leak to escape VM and get
root code exec on host - by Xiao Wei from 360 ESG Vuln Research Institute
who has previously found lots of QEMU bugs - $60k
Still waiting on upstream qemu / docker to release details - Firefox
already patched in CVE-2020-26950
Github writeup of GDM/accountsservice vulnerabilities [02:53]