BSides Joburg 2026

Tyron Kemp

Tyron Kemp is a cybersecurity professional with with a background spanning network engineering, penetration testing, and deception technology. He is perhaps best known for his Black Hat USA 2020 briefing, Routopsy: Modern Routing Protocol Vulnerability Analysis and Exploitation, co-presented with Szymon Ziolkowski at SensePost, where he exposed how misconfigured dynamic routing and first-hop redundancy protocols can be weaponised for person-in-the-middle attacks, releasing an open-source toolkit alongside the research.

In recent years, Tyron has worked where offensive tradecraft, detection engineering, and deception technologies overlap, helping organisations understand how attackers operate and how to reduce risk in ways that matter.

In his BSides Joburg 2026 talk, Pipe Dreams, he turns his attention to the endpoint by walking through how he escalated privileges to SYSTEM via Cooler Master's MasterPlus software, because sometimes the most dangerous vulnerabilities are hiding in the software you least expect.


Session

07-25
15:05
45min
Pipe Dreams: Escalating to SYSTEM via Cooler Master MasterPlus
Tyron Kemp

Every gaming peripheral that ships to your desk comes bundled with software running silently as NT AUTHORITY\SYSTEM. These OEM utilities are trusted, rarely audited, and almost never patched.

In this talk I walk through the discovery and exploitation of a local privilege escalation vulnerability in Cooler Master MasterPlus. A peripheral management suite installed on millions of Windows machines. The root cause is an unauthenticated named pipe exposed by MPService.exe (SYSTEM). Any standard local user can connect, send a single JSON payload, and execute arbitrary commands as SYSTEM with no admin rights, no user interaction, and no race condition required.

I'll cover the full methodology: service enumeration, pipe discovery, Ghidra static analysis, dynamic confirmation, and a working proof-of-concept.

Track 1