FIXX: FInding eXploits from eXamples
Neil P Thimmaiah
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Web Security
Overview
The talk "FIXX: FInding eXploits from eXamples," presented by Neil P Thimmaiah at the 34th USENIX Security Symposium, introduces a novel automated approach to identify undisclosed variants of known vulnerabilities within web applications. Addressing a critical gap in current vulnerability detection and patching methodologies, FIXX aims to move beyond single-instance fixes by leveraging information from disclosed exploits to uncover similar, previously undetected exploitable paths. This work, co-authored with Yashu Professor and Professor Benadrushman, directly tackles the pervasive issue of "chain-style vulnerabilities" where malicious data flows from input sources to sensitive operation sinks in web applications, often leading to zero-day exploits.

Key moments
- 0:00 Introduction to FIXX and chain-style vulnerabilities problem
- 2:00 Illustrative example: disclosed vs undisclosed vulnerability
- 4:20 FIXX's core solution: finding all exploitable path instances
- 5:10 FIXX's first step: Exploit Executioner and path extraction
- 6:15 Defining Instruction Similarity using AST subtrees
- 7:10 Introducing Path Similarity based on shared instruction nodes
FIXX: FInding eXploits from eXamples
Speakers: Neil P Thimmaiah
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=qfdy_WDTfQ0
Overview
The talk "FIXX: FInding eXploits from eXamples," presented by Neil P Thimmaiah at the 34th USENIX Security Symposium, introduces a novel automated approach to identify undisclosed variants of known vulnerabilities within web applications. Addressing a critical gap in current vulnerability detection and patching methodologies, FIXX aims to move beyond single-instance fixes by leveraging information from disclosed exploits to uncover similar, previously undetected exploitable paths. This work, co-authored with Yashu Professor and Professor Benadrushman, directly tackles the pervasive issue of "chain-style vulnerabilities" where malicious data flows from input sources to sensitive operation sinks in web applications, often leading to zero-day exploits.
The significance of FIXX lies in its ambition to provide "complete accuracy" in vulnerability patching, a concept championed by Google Project Zero. Traditional static application security testing (SAST) tools, while effective at identifying initial vulnerabilities, frequently fall short by reporting only a single instance of a flaw, thereby overlooking numerous variants. This oversight necessitates the publication of redundant CVEs for what are essentially the same underlying bug, or worse, leaves applications vulnerable to slightly modified attack vectors. FIXX proposes a systematic way to proactively discover these variants, thereby reducing false negatives and enabling developers to implement more comprehensive and robust security patches.
By taking an existing exploit path as an example, FIXX systematically explores an application's codebase to identify structurally and functionally similar data flows that could also be exploited. This approach is particularly relevant in an era where a significant portion of reported CVEs are merely variants of previously disclosed issues. The research presented demonstrates FIXX's capability to automate the discovery of these elusive variants, providing a critical tool for enhancing the security posture of web applications and streamlining the vulnerability disclosure and patching process.
Background
▶ Watch: Introduction to FIXX and chain-style vulnerabilities problem (0:00)
The landscape of cybersecurity in recent years has been dominated by a surge in exploits, particularly zero-day exploits, many of which revolve around chain-style vulnerabilities. These vulnerabilities are characterized by the flow of malicious data from untrusted input locations, termed sources, to sensitive operations, known as sinks, within web applications. Examples include SQL Injection (SQLi) where untrusted input reaches a database query, or Cross-Site Scripting (XSS) where it ends up in a browser's DOM for execution.
Current methods for detecting such vulnerabilities primarily involve Static Application Security Testing (SAST) tools. These tools employ sophisticated techniques like symbolic execution and constraint solving to identify potential exploitable paths. While SAST tools have been instrumental in discovering and reporting numerous vulnerabilities, often leading to CVE assignments, they suffer from a significant limitation: they frequently focus on detecting only a single instance of a vulnerability. This narrow focus leads to incomplete patches, where the immediate exploitable path is fixed, but similar variants elsewhere in the application remain unaddressed.
This problem of incomplete patching is not merely an academic concern; it has real-world consequences. Google Project Zero, a prominent security research team, highlighted that approximately one out of every four detected zero-day exploits could have been avoided if a more thorough investigation and patching effort had been undertaken. Their assertion that a "correct patch" is one that fixes a bug with "complete accuracy," preventing the discovery of any further variants, underscores the critical need for more comprehensive vulnerability detection. Statistics from 2023 and 2024 further illustrate this issue, with roughly 25% of published CVEs being identified as variants of existing vulnerabilities, suggesting that initial patches were often insufficient. These "unnecessary" CVEs could have been avoided if the original patching effort had encompassed all similar exploitable paths.
The core problem FIXX seeks to address is therefore: given a disclosed vulnerability, can we identify other similar, undisclosed vulnerabilities that haven't been found or reported as CVEs? This challenge arises because SAST tools, by focusing on individual instances, inherently produce numerous false negatives, failing to detect the full scope of an underlying vulnerability pattern. FIXX's approach aims to mitigate this by systematically exploring for variants, thereby reducing the proliferation of variant-specific CVEs and enhancing the overall efficacy of security patching.
Key Findings
▶ Watch: FIXX's core solution: finding all exploitable path instances (4:20)
FIXX has demonstrated significant success in identifying previously undisclosed exploitable paths, directly addressing the problem of incomplete vulnerability patching. The evaluation of FIXX involved 19 popular PHP applications, ranging from a few lines of code to approximately 255,000 lines across 10,000 PHP files. From a pool of 300 CVE entries, FIXX was able to reproduce 132 known exploits. Crucially, for 32 of these reproduced CVEs, FIXX discovered additional, similar exploitable paths that had gone undetected by prior methods.
The most compelling outcome of this research is the submission of 10 new CVEs to MITRE, a testament to FIXX's ability to unearth novel vulnerabilities. These newly discovered vulnerabilities, identified across the evaluated applications, were variants of the original, known CVEs, confirming the prevalence of incomplete patching and the utility of FIXX's variant analysis approach. The tool proved effective across different types of vulnerabilities, specifically demonstrating success in uncovering multiple similar exploitable paths for both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities.
Beyond the sheer number of discovered paths, FIXX exhibits a robust characteristic: it can rediscover the original CVE path from the newly found similar CVEs, establishing a bidirectional relationship that validates its accuracy and comprehensive coverage. The evaluation also provided insights into the optimal configuration parameters for FIXX, such as the similarity threshold and similarity modulo. It was observed that a similarity threshold of around 60% proved optimal for concentrating the detection of similar paths, balancing between finding truly similar paths and avoiding overly strict matches that could lead to false negatives. Similarly, a similarity modulo of two was found to be effective, indicating that allowing for a small number of differing named nodes in AST subtrees significantly aids in variant discovery without compromising relevance. The study concluded that the number of similar paths uncovered is directly proportional to the similarity modulo and inversely proportional to the similarity threshold.
Furthermore, FIXX's performance was benchmarked against three other vulnerability detection tools: Navix (a static and dynamic approach), RIPs (a static approach), and Clone Doctor (a code clone detection tool). While Navix and RIPs were able to detect a subset of the exploitable paths found by FIXX, they consistently identified fewer variants. Clone Doctor, designed for code clone detection rather than vulnerability variant analysis, was not able to detect the similar blocks of code relevant to the exploitable paths, highlighting FIXX's specialized capability in this domain. This comparative analysis firmly establishes FIXX's superior effectiveness in comprehensively identifying variant exploitable paths.
Technical Deep Dive
▶ Watch: FIXX's first step: Exploit Executioner and path extraction (5:10)
FIXX addresses the critical problem of discovering undisclosed vulnerabilities that are similar to a known, disclosed exploit. Its methodology is structured into several innovative steps, leveraging both dynamic execution and static code analysis.
The core idea is to move beyond finding new zero-day exploits and instead focus on reducing false negatives in existing vulnerability detection by comprehensively identifying every possible instance of an exploitable path related to a known vulnerability. This is achieved by taking the information from a CVE, executing the disclosed vulnerable path, and then using the insights from this execution to find similar paths elsewhere in the application.
Step 1: The Exploit Executioner
The first stage of FIXX involves understanding and reproducing the known vulnerability.
- Obtain CVE Details: FIXX begins by parsing the details provided in a CVE report, which typically includes information about the vulnerability type, affected components, and sometimes even a proof-of-concept.
- Reproduce Exploit: Using this information, FIXX constructs and executes a malicious payload to trigger the known exploit. This dynamic execution is crucial for understanding the actual data flow.
- Obtain Code Trace: During the exploit's execution, FIXX captures a detailed trace of the code. This trace records the sequence of instructions executed from the point where the malicious input originates (source) to where it performs its sensitive operation (sink). This specific sequence is termed the exploit path.
- Extract Exploit Path Subgraph: From the linear execution trace, FIXX extracts the data flow path. To provide a more complete contextual understanding, control dependencies (e.g., if-statements, loops that influence the path) are added to this data flow to create a comprehensive subgraph representing the exploit's structure within the application's overall Program Dependence Graph (PDG).
Similarity Notions
A cornerstone of FIXX's ability to find variants is its definition of similarity at both the instruction and path levels.
- Instruction Similarity: Two instructions in the application's graph are considered similar modulo X if their Abstract Syntax Tree (AST) subtrees have the same structure and node types, with exactly X corresponding name nodes that are different. For instance, if two instructions like
red_conf_value = request.GET['value']andget_conf_value = request.POST['value']have identical AST structures and node types, butred_conf_valuediffers fromget_conf_value(one name node) andGETdiffers fromPOST(another name node), they would be similar modulo 2. The value of X (the modulo) allows for a configurable degree of flexibility, enabling the detection of variants that are not exact syntactic matches.
- Path Similarity: A newly detected path is considered similar to the original exploit path if at least N% of its instruction nodes are instruction-similar (modulo X) to corresponding nodes in the original path. The percentage N is a configurable threshold. For example, if the threshold is 80% and a candidate path has four out of five nodes that are instruction-similar to the original path, it would be deemed a similar path. This metric allows FIXX to identify paths that maintain the overall exploitable logic while exhibiting some structural differences.
Novel Metrics: Reusability, Sensitivity, and Selectivity Scores
To efficiently identify critical points for variant analysis, FIXX introduces three novel metrics:
- Reusability Score: For any given instruction, this score quantifies how often that instruction (or an instruction instruction-similar to it) is repeated or used in different parts of the application's codebase. High reusability suggests a common pattern.
- Sensitivity Score: This score measures the cruciality or importance of an instruction to an exploit. An instruction is highly sensitive if its modification or presence significantly impacts the exploit's success or the malicious data's flow towards a sink.
- Selectivity Score: This is the product of the reusability score and the sensitivity score. It serves as a combined measure to identify instructions that are both commonly used and vital to an exploit's success. Instructions with high selectivity scores are deemed "important instructions" and are designated as seeds.
Seed Extraction and Candidate Instruction Identification
FIXX extracts these seeds from the original exploit path. These seeds represent the critical junctures or operations within the vulnerable data flow that are most indicative of the exploit's nature. Once seeds are identified, FIXX uses the instruction similarity notion (modulo X) to find other candidate instructions elsewhere in the application that are similar to these extracted seeds. This step broadens the search from the specific exploit path to the entire application's codebase, looking for analogous vulnerable patterns.
Path Detection and Verification
The final stage involves constructing and validating new exploitable paths:
- Detect S-paths and D-paths: For each candidate instruction found, FIXX attempts to identify two types of sub-paths:
- S-paths (Source Paths): Paths from any potential source node in the application to the candidate instruction.
- D-paths (Destination Paths): Paths from the candidate instruction to any potential sink node in the application.
- Uncover Exploitable Paths: By concatenating an S-path with a D-path through a candidate instruction, FIXX uncovers potential new exploitable paths that are similar to the original exploit path.
- Symbolic Execution and Verification: To confirm the executability and exploitability of these newly identified paths, FIXX performs symbolic execution. It uses an SMT (Satisfiability Modulo Theories) solver, specifically Z3, to determine if there exist inputs that can traverse the path and trigger the malicious operation at the sink. This step is crucial for verifying that the detected paths are indeed exploitable and not just structurally similar code.
By combining dynamic execution for initial exploit understanding with advanced static analysis techniques and similarity notions, FIXX provides a powerful and automated framework for comprehensive vulnerability variant detection.
Demo / Proof of Concept
▶ Watch: Defining Instruction Similarity using AST subtrees (6:15)
While the talk did not feature a live, interactive demonstration in the traditional sense, the speaker presented several conceptual examples and discussed the rigorous evaluation process that effectively serves as a large-scale proof of concept for FIXX's capabilities.
The initial problem statement was illustrated with a compelling example of a CVE-inspired application code. This example depicted a disclosed exploitable path where malicious input from two sources flowed to a database query and was then retrieved and executed at a sink. Crucially, the example then highlighted a similar, undisclosed vulnerability elsewhere in the same application, featuring two different source statements, a different query, and two distinct sync locations. This visual comparison effectively demonstrated the very problem FIXX aims to solve: the existence of functionally identical, yet syntactically distinct, vulnerable code paths that go undetected.
Furthermore, the explanation of instruction similarity was accompanied by a clear visual demonstration using two lines of code and their corresponding Abstract Syntax Tree (AST) subtrees. This illustrated how two instructions could have identical AST structures and node types, differing only in specific name nodes (e.g., red_conf_value versus get_conf_value). This concrete example provided a tangible understanding of the "modulo X" concept. Similarly, the path similarity concept was demonstrated with graphical representations of two paths, showing how a candidate path could be deemed 80% similar to an original exploit path based on instruction similarity.
The ultimate "proof of concept" for FIXX's efficacy lies in its comprehensive evaluation results. The research involved reproducing 132 known CVEs across 19 PHP applications and, more significantly, identifying 1097 new exploitable paths, leading to the submission of 10 new CVEs to MITRE. This extensive empirical validation, encompassing both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities, serves as a robust demonstration of FIXX's practical utility. The ability to systematically uncover these previously unknown variants across a diverse set of real-world applications is the strongest evidence of FIXX's power as a vulnerability analysis tool. The comparative analysis against tools like Navix and RIPs further underscored that FIXX's methodology successfully identifies a broader and more complete set of exploitable paths, effectively demonstrating its superior performance in variant detection.
Defensive Implications
▶ Watch: Introducing Path Similarity based on shared instruction nodes (7:10)
The findings and methodology presented by FIXX have profound implications for security defenders, developers, and organizations striving for robust application security. The primary takeaway is the critical need to move beyond single-instance vulnerability patching towards a more comprehensive approach that anticipates and addresses variants.
- Prioritize Comprehensive Patching: Defenders should adopt the "complete accuracy" standard advocated by Google Project Zero. This means that when a vulnerability is discovered and patched, the effort should not stop at fixing the immediate exploitable path. Instead, a thorough investigation, ideally automated by tools like FIXX, should be conducted to identify all similar exploitable paths or variants within the codebase. This proactive approach significantly reduces the likelihood of "patch gaps" that attackers can later exploit.
- Integrate Variant Analysis into SDLC: Security teams should integrate variant analysis tools and methodologies into their Software Development Lifecycle (SDLC). After an initial vulnerability report or a new CVE related to their software, running a tool like FIXX (or adopting its principles) can help ensure that all similar vulnerabilities are identified and patched before deployment. This shifts the focus from reactive firefighting to proactive prevention.
- Focus on High-Selectivity Code Segments: Developers can benefit from understanding FIXX's concepts of reusability and sensitivity scores. Identifying code segments or instructions that are both highly reused and highly sensitive to malicious input flows should become a priority for code review and security auditing. These "seeds" represent critical components where even minor flaws can lead to widespread vulnerabilities. Investing in securing these high-selectivity areas can yield significant security dividends.
- Enhance SAST/DAST with Variant Detection: While existing SAST and DAST (Dynamic Application Security Testing) tools are valuable, their limitations in detecting variants highlight a need for enhancement. Security tool vendors could integrate FIXX's principles, particularly its similarity notions and seed extraction, to improve the comprehensiveness of their offerings. Organizations should look for tools that offer variant analysis capabilities to complement traditional vulnerability scanning.
- Leverage Disclosed CVEs for Internal Scrutiny: Every disclosed CVE, whether for one's own product or similar technologies, should be treated as an "example" for internal scrutiny. Security teams can use the details of known exploits to inform targeted searches for similar patterns or logic flaws within their own applications, even if the exact vulnerable code isn't present. This allows for learning from the broader security community's discoveries to pre-emptively secure their own systems.
- Adopt a "Source-to-Sink" Data Flow Mindset: FIXX's focus on chain-style vulnerabilities (source-to-sink data flows) reinforces the importance of this architectural perspective. Defenders should rigorously map data flows from all untrusted inputs to all sensitive operations, ensuring proper sanitization, validation, and encoding at every step. This architectural understanding is fundamental to preventing the conditions that enable such exploits.
By embracing these defensive implications, organizations can move towards a more mature and effective application security posture, significantly reducing their attack surface and the cost associated with repeated vulnerability disclosures and emergency patching.
Key Takeaways
- Incomplete Patching is a Major Problem: A significant portion of reported CVEs (up to 25%) are variants of previously disclosed vulnerabilities, stemming from initial, incomplete patches that fail to address the root cause across all similar instances.
- FIXX Offers a Solution for Variant Discovery: FIXX is a novel, automated approach that leverages known exploit examples to systematically identify similar, previously undisclosed exploitable paths within web applications, thereby promoting "complete accuracy" in patching.
- Leverages Novel Similarity Notions and Metrics: FIXX introduces sophisticated concepts like instruction similarity (modulo X based on ASTs) and path similarity (percentage of similar instructions), combined with reusability, sensitivity, and selectivity scores to pinpoint critical "seed" instructions for variant analysis.
- Proven Effectiveness and Real-World Impact: FIXX successfully identified 1097 new exploitable paths across 19 PHP applications and led to the submission of 10 new CVEs to MITRE, demonstrating its practical utility for XSS and SQL Injection vulnerabilities.
- Superior to Existing Tools: Comparative analysis shows FIXX's enhanced capability over traditional SAST tools like Navix and RIPs in detecting a broader and more comprehensive set of exploitable paths.
- Empowers Defenders for Comprehensive Security: FIXX provides a framework for security teams to move beyond reactive patching, enabling proactive identification of vulnerability variants and fostering a more robust, preventative approach to application security.
About the Speaker(s)
The talk "FIXX: FInding eXploits from eXamples" was presented by Neil P Thimmaiah. The work was co-authored with Yashu Professor and Professor Benadrushman. Based on the presentation context, Neil P Thimmaiah is a researcher, likely affiliated with an academic institution, given the mention of professors as co-authors and the publication in the proceedings of the USENIX Security Symposium. The talk represents a significant contribution to the field of automated vulnerability detection and variant analysis in web applications.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid systems-security research with a clear problem statement, a novel automated pipeline, and real-world validation via 10 new CVEs submitted to MITRE. FIXX occupies a genuinely underserved niche — variant discovery from known-exploit examples — and backs the claim with numbers rather than hand-waving.
Heather Calloway (CISO) — WEAK
Technically credible research on vulnerability variant detection with real CVE submissions to validate it — but the talk never escapes the lab. The defensive implications section gestures at operator relevance without delivering it, and there is nothing here for a CISO, a security program leader, or a board.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)