Security Research
Showing results for 
Search instead for 
Do you mean 

Pwn2Own results for Wednesday (Day One)

Angela_Gunn ‎03-12-2014 07:24 PM - edited ‎03-12-2014 07:24 PM

The first day of Pwn2Own 2014 saw successful attempts by five entrants against five products, with payouts of $400,000 to researchers in the main competition and $82,500 to charity in the Pwn4Fun sponsors-only event.


At Pwn4Fun, Google delivered a very impressive exploit against Apple Safari launching Calculator as root on Mac OS X. ZDI presented a multi-stage exploit, including an adaptable sandbox bypass, against Microsoft Internet Explorer, launching Scientific Calculator (running in medium integrity) with continuation. Combined, the two efforts raised $82,500 for the Canadian Red Cross, the charity agreed upon by both sponsors.


The following vulnerabilities were successfully presented in the Pwn2Own competition:


By Jüri Aedla:

Against Mozilla Firefox, an out-of-bound read/write resulting in code execution.


By Mariusz  Mlynski:

Against Mozilla Firefox, two vulnerabilities, one allowing privilege escalation within the browser and one bypassing browser security measures.


By Team VUPEN:

Against Adobe Flash, a use-after-free with an IE sandbox bypass resulting in code execution.

Against Adobe Reader, a heap overflow and PDF sandbox escape, resulting in code execution.

Against Microsoft Internet Explorer, a use-after-free causing object confusion in the broker, resulting in sandbox bypass.

Against Mozilla Firefox, a use-after-free resulting in code execution.


All vulnerabilities were disclosed to their respective vendors in the Chamber of Disclosures, and each will be working to address those issues through their own processes.


The second and final day of Pwn2Own 2014 begins Thursday, March 13 at 10am PDT.

0 Kudos
About the Author


Leave a Comment

We encourage you to share your comments on this post. Comments are moderated and will be reviewed
and posted as promptly as possible during regular business hours

To ensure your comment is published, be sure to follow the Community Guidelines.

Be sure to enter a unique name. You can't reuse a name that's already in use.
Be sure to enter a unique email address. You can't reuse an email address that's already in use.
Type the characters you see in the picture above.Type the words you hear.
Jun 7-9
Las Vegas
Discover 2016 Las Vegas
Discover 2016 in Las Vegas, the ultimate showcase technology event for business and IT professionals to learn, connect, and grow.
Read more
Sep 13-16
National Harbor, MD
HPE Protect 2016
Protect 2016 is our annual conference and is the place to meet the world’s top information security talent, discuss new products and share information...
Read more
View all