logo

Microsoft Has Yet to Patch 7 Pwn2Own Zero-Days

ID: 65976b6c-0132-5b86-b4c0-adb57b0475fa

STIX ID: report--65976b6c-0132-5b86-b4c0-adb57b0475fa

Feed Name: Dark Reading

Threat Score
60/100

Date Published: 2024-05-17

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Seven unpatched Windows privilege-escalation vulnerabilities disclosed at Pwn2Own 2024 remain outstanding; they include use-after-free, TOCTOU, heap-based buffer overflow, privilege context switching errors, improper input validation, and race conditions. Researchers fully exploited these bugs during the competition, and while Microsoft says it is working on fixes within the 90-day disclosure timeline there is no indication yet of malicious actors exploiting them in the wild. Security experts warn such escalation bugs are commonly paired with remote code execution flaws to achieve system compromise, making timely patches important given Windows' widespread use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.