Theori BLOG
Offensive Security Insights
Subscribe for expert updates and emerging threat trends.
Subscribe for expert updates and emerging threat trends.
Finding Vulnerabilities in Firmware with Static Analysis Platform QueryX
QueryX, Theoriâs program analysis platform, automates variant analysis for vulnerability detection. Learn how its taint analysis module uncovered CVE-2023-39471.
Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024â27394)
CVE-2024-27394 is a TCP-AO Use-After-Free vulnerability caused by improper RCU API usage. Read the in-depth analysis and reliable triggering technique.
Chaining N-days to Compromise All: Part 6 â Windows Kernel LPE: Get SYSTEM
The final part of the N-day exploit series analyzes CVE-2023-36802, a privilege escalation vulnerability in mskssrv.sys, used to gain SYSTEM access on a VMware host.
Chaining N-days to Compromise All: Part 5 â VMware Workstation Guest-to-Host Escape
CVE-2023-20869 was exploited to achieve arbitrary code execution on a VMware host from a guest system. Read the full technical analysis.