
Maher Azzouzi
@maherazz2
Followers
1K
Following
724
Media
10
Statuses
142
Vulnerability Research & Exploit Development
Joined September 2022
Oracle's April 2024 Critical Patch Update includes my discovery of CVE-2024-21103, a race condition in VirtualBox's SUID binaries for Linux, CVSS score of 7.8 (high severity). #cve #virtualbox #oracle #linux #cybersecurity
3
6
30
RT @azz_maher: I wrote an LPE for CVE-2014-3153 AKA Towelroot, a bug in the Linux Kernel that was used to root Android devices earlier. The….
0
74
0
RT @azz_maher: I wrote an LPE exploit for CVE-2017-11176 for Linux Kernel version 4.8.11, I managed to bypass SMEP and SMAP (by stack pivot….
0
177
0
it's interesting that the very first CVE ever assigned was #CVE-1999-0001 remote DoS in BSD-derived TCP/IP implementations :).
0
0
5
good read off by one leading to free list corruption, write-what-where. Cool stuff.
Iconv, set the charset to RCE: in the first blog post of this series, @cfreal_ will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961)
0
0
4
RT @_simo36: I've audited the Android kernel in late 2023, and reported 10+ kernel bugs to Google, along with 2 exploits. Today, I'm releas….
0
263
0