Erik Egsgard

ZeroDay to Zero Dollars: Exploiting the Windows Management Instrumentation Device

Abstract

Many conference talks cover a researcher’s triumphant journey from vulnerability discovery to flawless exploitation, ending with bug bounties and hacking competition victories. This is not that talk. Instead, this presentation explores the harsh reality of modern vulnerability research. It is the story of hunting for a zero day Windows Local Privilege Escalation (LPE) destined for a hacking competition, successfully weaponizing it, and then watching the payout evaporate entirely due to unlucky timing and an inconvenient patch.

BIO

Erik Egsgard is a Principal Security Developer and vulnerability researcher specializing in Windows security and operating system architecture. At Field Effect, he focuses on low-level reverse engineering and EDR detection capabilities. Erik is a regular contributor to the vulnerability research community, frequently presenting his original work at security conferences, and regularly disclosing high-severity vulnerabilities.