The world’s economy relies heavily on C/C++ applications, yet a staggering 70% of CVEs affecting these applications are due to memory safety flaws. Rewriting all code in memory-safe languages is infeasible, necessitating smarter approaches. In this talk, you'll learn about a simplified threat model to guide efforts, how adversaries search for memory safety flaws, and multiple strategies to incrementally reduce risk. You'll also hear war stories about successfully driving change, providing you with practical insights to enhance your own security efforts.
Learning Objectives: