Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Pwn2Own 2011: IE8 on Windows 7 hijacked with 3 vulnerabilities

Pwn2Own 2011: IE8 on Windows 7 hijacked with 3 vulnerabilities

Ron Ron
August 25, 2019
1 min read

Thought Internet Explorer 8 on Windows 7 was secure? Think again. During a hacking challenge at Pwn2Own, Microsoft’s Internet Explorer 8 was successfully hacked by an Irish security researcher (Stephen Fewer) on a Windows 7 SP1 machine. This was all possible using three different vulnerabilities and exploitation techniques.

As ZDNet reports, the hacker used two different zero-day flaws in Internet Explorer to get “reliable code execution” and then “chained a third vulnerability to jump out of the IE Protected Mode sandbox.” This attack eventually bypassed the Data Execution Prevention (DEP) and Address Space Layout Administration (ASLR). These are two protection mechanisms built into Windows 7.

How long did it take to create the exploit? According to Stephen Fewer, it took him about five to six weeks to find the vulnerabilities and write a reliable exploit. “Writing the exploit was the tricky part. It was very time consuming, especially bypassing protected mode.” Fewer went on to say, “If you spend long enough looking for bugs, you’ll always find something.”

Details of the vulnerabilities will be kept tight lipped until a patch is released. What was the prize for his efforts? Stephen Fewer won a $15,000 cash prize and a new Windows laptop.

Further reading: Internet Explorer, Pwn2Own

Share this article:
Tags:
Internet Explorer Pwn2Own
Previous Article First impressions of the Designer Bluetooth Desktop from Microsoft Hardware Next Article Supreme Court to decide fate of Microsoft, i4i case

Related Articles

Chrome and Gemini icons representing Gemini Live voice assistant integration in Chrome

Chrome tests Gemini Live voice assistant in a floating overlay panel

March 14, 2026

Chrome’s Organizer feature may sync Gemini and AI conversations across devices

March 14, 2026

After Chrome, Edge tests launching the browser automatically when you sign into Windows

March 13, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Gemini Live voice assistant in a floating overlay panel
  • Chrome’s Organizer feature may sync Gemini and AI conversations across devices
  • After Chrome, Edge tests launching the browser automatically when you sign into Windows
  • iPhone Fold Latest Rumors: Display, Cameras, RAM and Price Details Revealed
  • Samsung fears first mobile operating loss due to memory price surge

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy