The 2023 Pwnie Nominee For Most Under-Hyped Research

LPE and RCE in RenderDoc, CVE-2023-33865 & 33864

Qualys

A reliable, one-shot remote exploit against the latest glibc malloc, in 2023! Plus a fun local privilege escalation involving XDG and systemd. This is a repeat from the Best Desktop Bug category, but the days of one-shot RCEs are few and far between now, and this is one of the few that we’ve seen, at least this year.