Wednesday, 30 April 2025

Enhancing Automatic Vulnerability Discovery for Windows RPC/COM in New Ways

In recent years, Microsoft Remote Procedure Call (RPC) and Component Object Model (COM) have become significant focal points in security research due to their vast attack surfaces to LPE and RCE vulnerabilities. The research community has done extensive research in this field. However, prior research have predominantly relied on pre-existing vulnerability patterns, this usually requires a lot of time and effort in reverse engineering. Additionally, fuzzing RPC/COM interfaces typically demands customized corpus and fuzzers tailored to interface definitions for each individual interface, resulting in inefficiency and complexity.... By: R4nger, Fangming Gu & Zhiniang Peng Full Abstract & Presentation Materials: https://ift.tt/pmsBXbE

source https://www.youtube.com/watch?v=VQiQuLo0v58

No comments:

Post a Comment