XX·001 Talk 2025
7 Vulns in 7 Days: Breaking Bloatware Faster Than It's Built
- Region
- Unattributed
- Language
- EN
Abstract
Bloatware. We all hate it, and most of us are good at avoiding it. But some vendor tools – especially those managing critical drivers – can be useful when the Windows Update versions aren't good enough for performance-critical computing. What started as a routine driver update took a sharp turn when I confirmed a reboot modal… from my browser. Wait, my browser shouldn't be able to do that!? To my disappointment (and maybe some surprise), it turned out to be arbitrary code execution – right from the browser. This kicked off a week-long deep dive, uncovering seven CVEs in seven days across several prominent vendors, all exploiting a common pattern: privileged services managing software on Windows with little regard for security.
Sources
- Watch the recording youtube.com
- Where this entry came from youtube.com
No archived mirror recorded yet. Regional conference sites go dark often — adding a Wayback link keeps this entry usable.
Source of truth:
data/works/7-vulns-in-7-days-2025.yaml