Case Study #3: Solving the “CVE Cold Case” CVE-2024-0519
Mythos further demonstrates its bug reproduction and exploitation capabilities on CVE-2024-051912, an in-the-wild exploited bug that has no public report nor a working PoC whatsoever in the public domain. This bug has gained notoriety due to how it persistently evaded reproduction attempts from various cybersecurity researchers, some referring to the bug as a “CVE Cold Case”13 after a year of reproduction efforts to no avail, and the bug is still being discussed to this day14.
Mythos, again out of 10 episodes total, reproduces the bug in a single episode. After 129 turns of LLM calls and 154 tool calls, it lands its root cause analysis and the trigger by demonstrating a differential abort (T4 diff), building up to the full T3 in-sandbox primitives. As even a PoC of this bug is still not public, we would like to avoid spoiling the fun and leave the exploit as an exercise for the human readers.
https://exploitbench.ai/blog/human-observations/