
Overview

FLASH SALE: Ends May 22!
Udemy online courses up to 85% off.
Get Deal
This 40-minute Black Hat conference talk explores innovative approaches to automatic vulnerability discovery in Microsoft Remote Procedure Call (RPC) and Component Object Model (COM) systems. Learn how security researchers R4nger, Fangming Gu, and Zhiniang Peng address the limitations of traditional vulnerability detection methods that rely on pre-existing patterns and require extensive reverse engineering. Discover more efficient techniques that move beyond the customized corpus and interface-specific fuzzers that have made RPC/COM security testing inefficient and complex. Gain insights into new methodologies that can help identify Local Privilege Escalation (LPE) and Remote Code Execution (RCE) vulnerabilities across these expansive attack surfaces.
Syllabus
Enhancing Automatic Vulnerability Discovery for Windows RPC/COM in New Ways
Taught by
Black Hat