Operation_WizardOpium__2020__The_zero-day_exploits_of_Operation_WizardOpium_Securelist.pdf
ID: c1cb5b02-bb6e-487f-96e9-9737ad9f206a
STIX ID: report--c1cb5b02-bb6e-487f-96e9-9737ad9f206a
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2020-05-29
Last Modified Date: 2020-05-29
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical analysis of Operation WizardOpium describes a watering-hole campaign that chained a Chrome WebAudio use-after-free vulnerability (CVE-2019-13720) with a Win32k elevation-of-privilege zero-day (CVE-2019-1458) to escape the browser sandbox and execute a Reflective PE loader which deployed malware. The report walks through exploitation primitives (heap grooming, PartitionAlloc metadata manipulation, arbitrary read/write), WASM/JIT RWX abuse to place shellcode, and kernel exploitation techniques (SetWindowLongPtr abuse, Bitmap abuse, token theft) used for privilege escalation and persistence.
