The 2018 Pwnie Nominee For Best Privilege Escalation Bug

Holey Beep

Credit: Anonymous (As well they should be with that shameful branding)

Holey Beep (CVE-2018-0492) is the latest breakthrough in the field of acoustic cyber security research. At least, that’s what this submission’s crappy website said. We were ready to delete this one, but upon further reading, it’s a fun race condition that abuses both signal handlers and uninitialized memory to achieve an arbitrary write. Also, pretty impressive that they had the audacity to submit /usr/bin/beep flaw when Spectre and Meltdown were clearly going to be on the list.