Guest Revolution: Our Story of Compromising the Host Kernel from the VMware Guest

No ratings

Presented at Hexacon 2024 by

In this presentation, we talk about our VMware full chain exploitation showcased at Pwn2Own 2024. We discuss the architecture and attack surface of VMware, followed by a technical analysis into the vulnerabilities we exploited, including information leakage and arbitrary code execution. And we cover our approach to exploiting these vulnerabilities, especially focusing on the challenges we faced and the methodologies to overcome them. Additionally, we will cover a Windows Kernel Elevation of Privilege vulnerability, introducing new exploitation primitive techniques. We then demonstrate how we chained these exploits to achieve a comprehensive attack, concluding with insights and future implications of our work.