KVM Bugs and an iOS IOMFB Kernel Exploit [Binary Exploitation]

Published: Dec. 2, 2021, 1 a.m.

Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/kvm-bugs-and-an-ios-iomfb-kernel-exploit.html

\n

Starting off this week with the new humble bundle and some discussion about hacking books. Then onto the vulns, some OOB access, uninitalized memory, and iOS exploit strategy.

\n

[00:00:17] Spot the Vuln - Counting Widgets

\n

[00:02:36] Humble Book Bundle: Hacking by No Starch Press

\n

[00:17:14] KVM: SVM: out-of-bounds read/write in sev_es_string_io

\n

[00:23:42] Anker Eufy Homebase 2 home_security CMD_DEVICE_GET_SERVER_LIST_REQUEST out-of-bounds write vulnerability

\n

[00:34:14] Apple ColorSync: use of uninitialized memory in CMMNDimLinear::Interpolate

\n

[00:40:16] Popping iOS <=14.7 with IOMFB

\n

The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:

\n

    \n
  • Mondays at 3:00pm Eastern (Boston) we focus on web and more bug bounty style vulnerabilities
  • \n
  • Tuesdays at 7:00pm Eastern (Boston) we focus on lower-level vulnerabilities and exploits.
  • \n
\n

The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec

\n

You can also join our discord: https://discord.gg/daTxTK9

\n

Or follow us on Twitter (@dayzerosec) to know when new releases are coming.