#NullconBerlin2025 | RDP and The Power of Deterministic Snapshot Fuzzing by Pascal Beyer
About this talk
This talk, presented by Pascal Beyer, explores the power of deterministic snapshot fuzzing in the context of attacking the Microsoft Remote Desktop Client. Beyer discusses how specialized tools and emulators, like SNAFUzz, enhance the fuzzing process and allow for better analysis of security vulnerabilities. By reviewing three recent CVEs, including a kernel vulnerability and a heap memory leak, he demonstrates the effectiveness of emulators in pinpointing and reproducing vulnerabilities such as CVE-2025-32715 and a remote code execution issue in the RDP Client. This session highlights the advantages of employing emulator features like allocation tracking and out-of-bounds detection for comprehensive vulnerability assessment.
More from this event
See all 16 talks →
#NullconBerlin2025 | Panel: Industrial Systems In The Crosshairs: What It Really Takes To Defend OT
51:53
#NullconBerlin2025 | Stealing All macOS Sensitive Info with a Single Vulnerability by Koh
29:22
#NullconBerlin2025 | Derandomizing Kernel Object Locations w Software Hardware-Induced Side Channels
37:23
#NullconBerlin2025 | Your MCP Server Executes Commands - But From Whom? by Simcha Kosman
35:03