Black Hat USA 2012 - A Stitch in Time Saves Nine: A Case of Multiple Operating System Vulnerability
384 views · Published 10 October 2013 · 58:34 · Indexed 20 September 2026
Channel: Black Hat · 2013 · Education
BlackHat USA 2012 - By: Rafal Wojtczuk Six years ago Linux kernel developers fixed a vulnerability that was caused by using the "sysret" privileged Intel CPU instruction in an unsafe manner. Apparently, nobody realized (or cared enough to let others know) the full impact and how widespread and reliably exploitable the problem is: in 2012, four other popular operating systems were found to be vulnerable to user-to-kernel privilege escalation resulting from the same root cause. The presentation will explain the subtleties of the relevant Intel CPU instructions and the variety of ways they can be reliably exploited on unpatched systems. Exploits for a few affected operating systems will be demonstrated. Attendees are expected to have basic understanding of Intel CPUs architecture.
More from this channel
-
1:00:09
Black Hat USA 2000 - Advanced Windows NT/2K Security (II)
-
1:25:19
Black Hat USA 2003 - The Law of Vulnerabilities
-
1:01:51
Black Hat USA 2005 - Rogue Squadron: Evil Twins, 802.11intel, Radical RADIUS, & Weaponry for Windows
-
50:45
Black Hat USA 2012 - The Info Leak Era on Software Exploitation
-
1:19:53
Black Hat USA 2002 - Security Aspects in Java Bytecode Engineering
-
49:27
Black Hat Asia 2014 - Persist It: Using and Abusing Microsoft's Fix It Patches
-
29:49
Android FakeID Vulnerability Walkthrough
-
28:11
Resurrecting The Read_Logs Permission on Samsung Devices