Back to directory
WRITEUP #315

Lethal Injection: How We Hacked Microsoft's Healthcare Chat Bot

RCEChatbotSandbox escapeCross-tenant vulnerabilityMemory leak
by@Yanir_(Yanir Tsarimi)
Bounty
203,000
Program
Microsoft
Published
May 7, 2024
Added to HackDex
May 11, 2024
Read Full Writeuphttps://www.breachproof.net/blog/lethal-injection-how-we-hacked-microsoft-ai-chat-bot
RELATED WRITEUPS
Unveiling Remote Code Execution in AI chatbot workflows 💵
AI / LLMAI
Unveiling Remote Code Execution in AI chatbot workflows 💵
AI / LLMAI
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization

Built with ❤️ by Shubham Rawat