Nov. 29, 2023, 1 p.m. | DAY[0]

DAY[0] www.youtube.com

This week kicks off with a a V8 misoptimization leading to out-of-bounds access, an unprotected MSR in Microsoft's Hypervisor allowing corruption of Hypervisor code. We also take a quick look at a 2021 CVE with an integer underflow leading to an overflow in the Windows Kernel low-fragmentation heap, and finally an interesting information leak due to the kernel not clearing a sensitive register.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/228.html

[00:00:00] Introduction
[00:00:56] Spot the Vuln …

access binary binary exploitation bug bugs code corruption cve exploitation far fragmentation hypervisor integer ios kernel low microsoft out-of-bounds overflow podcast week windows windows kernel

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Information Security Specialist, Sr. (Container Hardening)

@ Rackner | San Antonio, TX

Principal Security Researcher (Advanced Threat Prevention)

@ Palo Alto Networks | Santa Clara, CA, United States

EWT Infosec | IAM Technical Security Consultant - Manager

@ KPMG India | Bengaluru, Karnataka, India

Security Engineering Operations Manager

@ Gusto | San Francisco, CA; Denver, CO; Remote

Network Threat Detection Engineer

@ Meta | Denver, CO | Reston, VA | Menlo Park, CA | Washington, DC