Close Menu
globalcrimedesk.comglobalcrimedesk.com
    What's Hot

    Gaza likely to dominate agenda as Arab League meets in Baghdad | Israel-Palestine conflict News

    Printer maker Procolored offered malware-laced drivers for months

    Trump’s DOJ focuses in on voter fraud, with help from DOGE : NPR

    Facebook X (Twitter) Instagram
    Trending
    • Gaza likely to dominate agenda as Arab League meets in Baghdad | Israel-Palestine conflict News
    • Printer maker Procolored offered malware-laced drivers for months
    • Trump’s DOJ focuses in on voter fraud, with help from DOGE : NPR
    • Million Palestinians could be relocated to war-torn Libya under US plans, report claims
    • Shining the spotlight on India’s dwindling Parsi community
    • Grok blames White genocide chat on ‘unauthorized mod’ • The Register
    • The assisted dying lobby isn’t being honest with you – disabled people are at risk from this bill | Lucy Webster
    • Three Iranian men charged under National Security Act
    Facebook X (Twitter) Instagram
    globalcrimedesk.comglobalcrimedesk.com
    • Home
    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention
    • Scandals
    • Terror
    • Trafficking
    globalcrimedesk.comglobalcrimedesk.com
    Home»Cyber»Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own
    Cyber

    Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own

    mediamillion1000@gmail.comBy [email protected]May 17, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
    Follow Us
    Google News Flipboard
    Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Hackers exploit VMware ESXi, Microsoft SharePoint zero-days at Pwn2Own

    During the second day of Pwn2Own Berlin 2025, competitors earned $435,000 after exploiting zero-day bugs in multiple products, including Microsoft SharePoint, VMware ESXi, Oracle VirtualBox, Red Hat Enterprise Linux, and Mozilla Firefox.

    The highlight was a successful attempt from Nguyen Hoang Thach of STARLabs SG against the VMware ESXi, which earned him $150,000 for an integer overflow exploit.

    Dinh Ho Anh Khoa of Viettel Cyber Security was awarded $100,000 for hacking Microsoft SharePoint by leveraging an exploit chain combining an auth bypass and an insecure deserialization flaw.

    Palo Alto Networks’ Edouard Bochin and Tao Yan also demoed an out-of-bounds write zero-day in Mozilla Firefox, while Gerrard Tai of STAR Labs SG escalated privileges to root on Red Hat Enterprise Linux using a use-after-free bug, and Viettel Cyber Security used another out-of-bounds write for an Oracle VirtualBox guest-to-host escape.

    In the AI category, Wiz Research security researchers used a use-after-free zero-day to exploit Redis and Qrious Secure chained four security flaws to hack Nvidia’s Triton Inference Server.

    On the first day, competitors were awarded $260,000 after successfully exploiting zero-day vulnerabilities in Windows 11, Red Hat Linux, and Oracle VirtualBox, reaching a total of $695,000 earned over the first two days of the contest after demonstrating 20 unique 0-days.

    Pwn2Own Berlin day two rankings
    Pwn2Own Berlin day two rankings (ZDI)

    ​​​The Pwn2Own Berlin 2025 hacking competition focuses on enterprise technologies, introduces an AI category for the first time, and takes place during the OffensiveCon conference between May 15 and May 17.

    Security researchers will be able to earn over $1,000,000 in rewards for demonstrating zero-day bugs in fully patched products in the AI, web browser, virtualization, local privilege escalation, servers, enterprise applications, cloud-native/container, and automotive categories.

    However, no Tesla attempts were registered before Pwn2Own started, even though two 2025 Tesla Model Y and 2024 Tesla Model 3 bench-top units were also available as targets.

    On the last day of the contest, the hackers will attempt to exploit zero-day bugs in Windows 11, Oracle VirtualBox, VMware ESXi, VMware Workstation, Mozilla Firefox, as well as Nvidia’s Triton Inference Server and Container Toolkit.

    After zero-day exploits are disclosed during the Pwn2Own contest, vendors have 90 days to release security fixes for their software and hardware products before Trend Micro’s Zero Day Initiative publishes technical details.

    Red Report 2025

    Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

    ESXi exploit Hackers Microsoft Pwn2Own SharePoint VMware zerodays
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWisconsin judge’s case is rare. There’s another near Boston : NPR
    Next Article Ukraine peace talks achieve little beyond prisoner swap pledge : NPR
    [email protected]
    • Website

    Related Posts

    Printer maker Procolored offered malware-laced drivers for months

    May 17, 2025

    Grok blames White genocide chat on ‘unauthorized mod’ • The Register

    May 17, 2025

    America’s CFPB bins proposed data broker crackdown • The Register

    May 17, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Posts

    Gaza likely to dominate agenda as Arab League meets in Baghdad | Israel-Palestine conflict News

    Printer maker Procolored offered malware-laced drivers for months

    Trump’s DOJ focuses in on voter fraud, with help from DOGE : NPR

    Million Palestinians could be relocated to war-torn Libya under US plans, report claims

    Trending Posts

    Gaza likely to dominate agenda as Arab League meets in Baghdad | Israel-Palestine conflict News

    May 17, 2025

    Printer maker Procolored offered malware-laced drivers for months

    May 17, 2025

    Trump’s DOJ focuses in on voter fraud, with help from DOGE : NPR

    May 17, 2025

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    News

    • Cyber
    • Global
    • Law
    • Mafia
    • Prevention

    Company

    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy policy
    • Terms & Condition
    Recent Posts
    • Gaza likely to dominate agenda as Arab League meets in Baghdad | Israel-Palestine conflict News
    • Printer maker Procolored offered malware-laced drivers for months

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2025 globalcrimedesk. Designed by Pro.
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    Type above and press Enter to search. Press Esc to cancel.