Discover the process of uncovering 16 Microsoft Office Excel vulnerabilities in just 6 months through this insightful conference talk from the Hack In The Box Security Conference. Learn how to build an effective fuzzing framework step-by-step, including selecting fuzzing corpus, implementing mutation algorithms, and triaging results. Gain valuable insights into automating dialog box interactions, managing temporary files, and optimizing fuzzing strategies. Explore real-world examples of remote code execution and information disclosure vulnerabilities, and understand the process of reporting findings to Microsoft Security Response Center. Benefit from the speaker's extensive experience in security research and vulnerability discovery, including tips for overcoming common challenges in the fuzzing process.
How I Found 16 Microsoft Office Excel Vulnerabilities in 6 Months