DEF CON 33 - 7 Vulns in 7 Days - Breaking Bloatware Faster Than It’s Built - Leon 'leonjza' Jacobs

DEF CON 33 - 7 Vulns in 7 Days - Breaking Bloatware Faster Than It’s Built - Leon 'leonjza' Jacobs

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 39:59

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This talk reveals how bloatware from major hardware manufacturers contains serious security vulnerabilities that allow remote code execution and privilege escalation 0:00.

Key Takeaways:
• ASUS DriverHub contained a "string contains" bug allowing arbitrary origins to interact with its local web server, leading to remote code execution 6:57
• MSI Center had multiple privilege escalation vulnerabilities, including a race condition in verification and an insecure execute task implementation 19:09
• Acer Control Center's named pipe was configured with "FILE_ALL_ACCESS" permissions, enabling remote code execution across the network 24:00
• Razer Synapse 4's elevation service had a COM interface that allowed unprivileged processes to launch applications with elevated privileges 35:36

All discovered vulnerabilities have been fixed in updated versions, but they highlight how common insecure RPC mechanisms are in bloatware 38:54.

Sources:

  • 0:00 Introduction to bloatware vulnerabilities
  • 6:57 ASUS DriverHub string contains bug
  • 19:09 MSI Center privilege escalation flaws
  • 24:00 Acer Control Center named pipe vulnerability
  • 35:36 Razer Synapse elevation service exploit
  • 38:54 Conclusion about bloatware security issues

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Welcome to my talk, Seven Valms in Seven Days, where we're going to be breaking bloatware faster than it's been built. To start this, I need to tell you a story of where I'm playing games. It's summer holiday back in South Africa. Uh I'm taking some time out uh and playing my favorite game. At the end of that session though, I notice at the bottom right ASUS DriverHub is asking me for install a driver update. Little confused by this, I click it and a browser opens up. This driverhub.asis.com uh is in a browser and it's asking me for more things to install. This is fairly confusing, but I continue with the progress. Eventually, a modal pops up asking me to restart now. Now, I've already been a little suspicious by this point, but I've been really suspicious right now. How could this be work…