logo

Operation_WizardOpium__2020__The_zero-day_exploits_of_Operation_WizardOpium_Securelist.pdf

ID: c1cb5b02-bb6e-487f-96e9-9737ad9f206a

STIX ID: report--c1cb5b02-bb6e-487f-96e9-9737ad9f206a

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2020-05-29

Last Modified Date: 2020-05-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical analysis of Operation WizardOpium describes a watering-hole campaign that chained a Chrome WebAudio use-after-free vulnerability (CVE-2019-13720) with a Win32k elevation-of-privilege zero-day (CVE-2019-1458) to escape the browser sandbox and execute a Reflective PE loader which deployed malware. The report walks through exploitation primitives (heap grooming, PartitionAlloc metadata manipulation, arbitrary read/write), WASM/JIT RWX abuse to place shellcode, and kernel exploitation techniques (SetWindowLongPtr abuse, Bitmap abuse, token theft) used for privilege escalation and persistence.