Feb. 2, 2024, 6:20 p.m. | Black Hat

Black Hat www.youtube.com

...In this talk, we will present severe security flaws that are universally present in the latest protections of commodity RTOSes, including Amazon's FreeRTOS, ARM's MbedOS, Microsoft's Azure ThreadX, Samsung's TizenRT, and rt-thread. These flaws encompass MPU misconfiguration, the absence of permission checks during mode switching, and more. We will describe our exploitation technique that takes advantage of these security flaws to easily escalate privilege and achieve arbitrary read and write. Through live-demos, we will showcase such exploitation targetting real-world products.... …

amazon arm azure flaws kill latest microsoft misconfiguration mode permission samsung security security flaws targeting

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)