Explore severe security vulnerabilities universally present in the latest protections of commodity Real-Time Operating Systems (RTOSes) in this 25-minute Black Hat conference talk. Discover how these flaws, including MPU misconfiguration and lack of permission checks during mode switching, affect popular systems like Amazon's FreeRTOS, ARM's MbedOS, Microsoft's Azure ThreadX, Samsung's TizenRT, and rt-thread. Learn about an exploitation technique that leverages these security weaknesses to escalate privileges and achieve arbitrary read and write capabilities. Witness live demonstrations showcasing the exploitation of real-world products, gaining valuable insights into the critical security challenges facing modern RTOSes.
Overview
Syllabus
Kill Latest MPU-based Protections in Just One Shot: Targeting All Commodity RTOSes
Taught by
Black Hat