About Me


Yuhao Jiang

/ former ctfer @ Vidar-Team

/ Security Researcher @ Ant Group Light-Year Security Lab

/ VMware Fusion VM Escape at GeekPwn 2022

/ Best Privilege Escalation at Pwnie Awards 2023

/ VMware ESXI VM Escape Tianfu Cup 2023

/ danisjiang [at] gmail [dot] com

/ Twitter (@danis_jiang)


BlackHat Asia & CanSecWest 2023: URB Excalibur: The New VMware All-Platform VM Escapes

BlackHat USA 2025: Dark Corners: How a Failed Patch Left VMware ESXi VM Escapes Open for Two Years

CVE List:

VMware: CVE-2022-31705, CVE-2024-22252

VirtualBox: CVE-2025-21571

LangChain: CVE-2024-27444

llama_index: CVE-2024-3271

llama.cpp: CVE-2024-32878

libavif: CVE-2025-48174, CVE-2025-48175