The winners of the annual Pwnie Awards 2021 have been announced, highlighting the most significant vulnerabilities and absurd failures in the realm of computer security. The Pwnie Awards are considered the equivalent of the Oscars and the Golden Raspberries in the field of cybersecurity.
Main Winners (List of Nominees):
- Best Privilege Escalation Vulnerability. Awarded to Qualys for discovering the CVE-2021-3156 vulnerability in the sudo utility, allowing for root privileges. This vulnerability was present in the code for nearly 10 years and is notable for requiring a thorough analysis of the utility's logic to uncover.
- Best Server Error. Awarded for discovering and exploiting the most technically complex and interesting error in a network service. The award goes to the identification of a new attack vector on Microsoft Exchange. Although not all vulnerabilities of this class have been disclosed, information has already been released about CVE-2021-26855 (ProxyLogon), which allows data extraction from arbitrary users without authentication, and CVE-2021-27065, enabling code execution with server administrator privileges.
- Best Cryptographic Attack. Awarded for identifying the most significant flaws in real systems, protocols, and encryption algorithms. The award goes to Microsoft for the vulnerability (CVE-2020-0601) in the implementation of digital signatures based on elliptic curves, allowing the generation of private keys from public keys. This issue allowed the creation of fraudulent TLS certificates for HTTPS and fake digital signatures that were verified as trustworthy in Windows.
- Most Innovative Research. The award was given to researchers who proposed the BlindSide method for bypassing address space layout randomization (ASLR) protections through side-channel leaks arising from speculative instruction execution by the processor.
- The Most Epic FAIL. The award was given to Microsoft for repeatedly releasing a non-functional fix for the PrintNightmare vulnerability (CVE-2021-34527) in the Windows printing system, which allowed for code execution. Initially, Microsoft marked the issue as local, but it later became clear that the attack could be performed remotely. Microsoft subsequently published updates four times, but each time the fix only addressed a specific instance, and researchers found new ways to carry out the attack.
- Best Client Software Error. The award went to the researcher who discovered the CVE-2020-28341 vulnerability in secure Samsung cryptoprocessors certified with CC EAL 5+. The vulnerability allowed complete bypass of security, access to executable code on the chip and data stored in the enclave, circumventing the screen lock, and modifying the firmware to create a hidden backdoor.
- The Most Underestimated Vulnerability. The award was given to Qualys for identifying a series of vulnerabilities known as 21Nails in the mail server Exim, 10 of which can be exploited remotely. Exim developers were skeptical about the possibility of exploiting these issues and spent more than 6 months developing fixes. server The Lamest Vendor Response. This nomination is for the most inadequate reaction to a notification of a vulnerability in the vendor's own product. The winner is Cellebrite, a company specializing in applications for forensic analysis and data extraction for law enforcement. Cellebrite reacted inadequately to the vulnerabilities notification sent by Moxie Marlinspike, the author of the Signal protocol. Moxie became interested in Cellebrite after a media report on the creation of a technology that could hack encrypted Signal messages, which later turned out to be a fake due to a misinterpretation of information in an article on Cellebrite's website that was subsequently removed (the 'attack' required physical access to the phone and the ability to unlock the screen, effectively reducing it to viewing messages in the messenger, but not manually, rather using a special application simulating user actions).
- The Lamest Vendor Response. A nomination for the most inadequate reaction to a report of a vulnerability in its own product. The winner was Cellebrite, a company that develops applications for forensic analysis and data extraction by law enforcement agencies. Cellebrite's response to the vulnerability report sent by Moxie Marlinspike, the author of the Signal protocol, was inadequate. Moxie became interested in Cellebrite after a media article mentioned technology enabling the hacking of encrypted Signal messages, which later turned out to be fake due to a misinterpretation of information on the Cellebrite website that was subsequently taken down (the 'attack' required physical access to the phone and the ability to unlock the screen, meaning it involved viewing messages in the messenger not manually, but using a special application simulating user actions).
Moxy examined Cellebrite applications and found critical vulnerabilities that allowed arbitrary code execution when attempting to scan specially formatted data. The Cellebrite application also revealed the use of an outdated ffmpeg library that had not been updated for 9 years and contained numerous unaddressed vulnerabilities. Instead of acknowledging the issues and addressing the problems, Cellebrite issued a statement claiming to care about user data integrity, maintain a proper level of security for its products, release updates regularly, and provide the best applications in their class.
- The greatest achievement. The award was given to Ilfak Guilfanov, the author of the IDA disassembler and Hex-Rays decompiler, for his contribution to the development of tools for security researchers and his ability to maintain a relevant product for 30 years.
Source: opennet.ru
