Edge, Ubuntu, Safari and Adobe: The Victims of Pwn2Own 2017
Pwn2Own

The 2017 edition of the Pwn2Own competition has ended, and what came out of it will keep the responsible parties busy for weeks (or maybe months). Eleven teams and thirty planned attacks brought various high-profile tools to their knees, including Ubuntu in its first participation, and Adobe resources like Reader and Flash. However, the true "sieve" of the party was Microsoft Edge, which hackers managed to manipulate to escape a virtual machine.

Pwn2Own 2017 in figures

Pwn2Own 2017 handed out more than $800,000 in three days, not counting the laptops the participating teams took home. The official page reports a total of 51 bugs, which obviously have already been presented to developers so they can implement the necessary patches. The teams are increasingly dedicated, cunning and creative, chaining vulnerabilities with a frightening naturalness. Of course, there were some last-minute withdrawals, failures for exceeding time limits, and disqualifications due to using already-reported bugs, but as for the rest... they left no stone unturned.

Ubuntu, Safari and Adobe

The one who got a bit of attention on the first day was Ubuntu, which yielded to the Chaitin Tech team that exploited a kernel bug and gained root access through the xcalc application. The vulnerability was relatively small, but enough to earn a prize of $15,000. Safari suffered three successful attacks and another that was partially recognized, since the bug used had been fixed in a later beta version. And Adobe didn't lose its habit of having big holes in Reader (in one case enabling remote code execution after the attacker combined three bugs), and Flash (privilege escalation).

Microsoft Edge: the glass jaw

But the glass jaw par excellence at Pwn2Own 2017 was Microsoft Edge. The browser integrated into Windows 10 was defeated five times, starting on the first day when the Team Ether from Tencent Security escaped the sandbox with a logic bug and an arbitrary write in the Chakra engine. The most spectacular attack against Edge came on the third day, with members of 360 Security completely escaping from a virtual machine. The first step was to combine a bug in Chakra and in the Windows kernel to achieve code execution within the sandbox, and then get out of it. With the guest system at their mercy, 360 Security slipped through an uninitialized buffer in VMWare Workstation, thus obtaining access to the host system. This trio gave 360 Security a total of $105,000, and crowned them winners (Tencent was very close, and their own VMWare escape was worth $100,000). We've known for a while that quality control at Microsoft has fallen apart, but what Edge did at Pwn2Own 2017 was scandalous. I hope Redmond releases an update soon.

Official site: