Maher Azzouzi Profile
Maher Azzouzi

@maherazz2

Followers
1K
Following
724
Media
10
Statuses
142

Vulnerability Research & Exploit Development

Joined September 2022
Don't wanna be here? Send us removal request.
@maherazz2
Maher Azzouzi
1 year
Oracle's April 2024 Critical Patch Update includes my discovery of CVE-2024-21103, a race condition in VirtualBox's SUID binaries for Linux, CVSS score of 7.8 (high severity). #cve #virtualbox #oracle #linux #cybersecurity
Tweet media one
3
6
30
@maherazz2
Maher Azzouzi
25 days
ZDI-CAN-27262 is a Linux kernel 0-day I reported recently that allows unprivileged users to escalate privileges to root. The vulnerability is a race condition leading to a UAF in the kmalloc-196 cache. It was introduced in v4.2-rc1 and has been present in the kernel for 10 years.
Tweet media one
4
47
244
@maherazz2
Maher Azzouzi
6 months
RT @azz_maher: I wrote an LPE for CVE-2014-3153 AKA Towelroot, a bug in the Linux Kernel that was used to root Android devices earlier. The….
0
74
0
@maherazz2
Maher Azzouzi
6 months
RT @azz_maher: I wrote an LPE exploit for CVE-2017-11176 for Linux Kernel version 4.8.11, I managed to bypass SMEP and SMAP (by stack pivot….
0
177
0
@maherazz2
Maher Azzouzi
7 months
in 2025: “How the bug was found? fuzzing, auditing or LLM?”.
3
1
19
@maherazz2
Maher Azzouzi
8 months
- Heap overflow in the latest AMDGPU drivers. CVSS score: 8.8, bounty: $5k. - 7 Android kernel vulnerabilities. It wasn’t a good idea to keep these bugs documented without reporting them for three months — one of them turned out to be a duplicate.
Tweet media one
Tweet media two
3
4
158
@maherazz2
Maher Azzouzi
9 months
CVE-2024-26926 Binder n-day analysis. It is labeled EoP in Android Security Bulletin (Is it really exploitable?).
5
41
170
@maherazz2
Maher Azzouzi
10 months
6998d993a027f9e430b9b3552a0d4374.
0
0
9
@maherazz2
Maher Azzouzi
11 months
Android Binder use-after-free vulnerability reported to Google by me
Tweet media one
5
7
183
@maherazz2
Maher Azzouzi
11 months
Found a lot of Linux kernel vulnerabilities, too little time for developing exploits, maybe im gonna pick the most interesting one and work on it. (probably report them as they are is an option 🤔?).
2
0
27
@maherazz2
Maher Azzouzi
1 year
NULL pointer dereference can be exploited for LPE with correct analysis.
1
0
28
@maherazz2
Maher Azzouzi
1 year
Linux kernel LPE for versions 6.6 to latest (6.9.7)
Tweet media one
3
6
75
@maherazz2
Maher Azzouzi
1 year
it's interesting that the very first CVE ever assigned was #CVE-1999-0001 remote DoS in BSD-derived TCP/IP implementations :).
0
0
5
@maherazz2
Maher Azzouzi
1 year
good morning, woke up to ssh and chrome vulns this morning, i have to read some technical blogposts after breakfast.
1
0
5
@maherazz2
Maher Azzouzi
1 year
good read off by one leading to free list corruption, write-what-where. Cool stuff.
@ambionics
Ambionics Security
1 year
Iconv, set the charset to RCE: in the first blog post of this series, @cfreal_ will show a new exploitation vector to get RCE in PHP from a file read primitive, using a bug in iconv() (CVE-2024-2961)
0
0
4
@maherazz2
Maher Azzouzi
1 year
Wrote a PoC LPE for a tiny race condition leading to UAF. CAP_NET_ADMIN is needed for the LPE. Based on my research all major distributions using a kernel > 6.6 are vulnerable including Ubuntu 24.04. I will be reporting the bug in the upcoming days - blogpost and PoC coming later
3
44
216
@maherazz2
Maher Azzouzi
1 year
took me 2 months to find a uaf, now it will take 2 years to write an exploit
Tweet media one
4
2
63
@maherazz2
Maher Azzouzi
1 year
CVE-2024-26817: Identified and reported an integer overflow causing heap overflow in AMD KFD. The issue was addressed by the Linux Kernel security team in commit 3b0daec. #Cybersecurity #infosec #linux #amd #ROCm #0day #cve
Tweet media one
2
4
22
@maherazz2
Maher Azzouzi
1 year
RT @_simo36: I've audited the Android kernel in late 2023, and reported 10+ kernel bugs to Google, along with 2 exploits. Today, I'm releas….
0
263
0
@maherazz2
Maher Azzouzi
2 years
Any bounty program for IoT?.
1
0
1