From Rookie to Expert: Manipulating LLMs for Automated Vulnerability Exploitation in Enterprise Software

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Diouf, Moustapha Awwalou, Diao, Maimouna Tamah, Olatunji, Iyiola Emmanuel, Kaboré, Abdoul Kader, Samhi, Jordan, Mendy, Gervais, Ouya, Samuel, Klein, Jacques, Bissyandé, Tegawendé F.
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866910158017265664
author Diouf, Moustapha Awwalou
Diao, Maimouna Tamah
Olatunji, Iyiola Emmanuel
Kaboré, Abdoul Kader
Samhi, Jordan
Mendy, Gervais
Ouya, Samuel
Klein, Jacques
Bissyandé, Tegawendé F.
author_facet Diouf, Moustapha Awwalou
Diao, Maimouna Tamah
Olatunji, Iyiola Emmanuel
Kaboré, Abdoul Kader
Samhi, Jordan
Mendy, Gervais
Ouya, Samuel
Klein, Jacques
Bissyandé, Tegawendé F.
contents LLMs democratize software engineering by enabling non-programmers to create applications, but this same accessibility fundamentally undermines security assumptions that have guided software engineering for decades. We show in this work how publicly available LLMs can be socially engineered to transform novices into capable attackers, challenging the foundational principle that exploitation requires technical expertise. To that end, we propose RSA (Role-assignment, Scenario-pretexting, and Action-solicitation), a pretexting strategy that manipulates LLMs into generating functional exploits despite their safety mechanisms. Testing against Odoo -- a widely used ERP platform, we evaluated five mainstream LLMs (GPT-4o, Gemini, Claude, Microsoft Copilot, and DeepSeek) and successfully exploited every tested CVE: at least one LLM produced a functional exploit for each within 3-5 prompting rounds. While prior work~\cite{jin2025good} found LLM-assisted attacks difficult and requiring manual effort, we demonstrate that this overhead can be eliminated entirely. Our findings invalidate core software engineering security principles: the distinction between technical and non-technical actors no longer provides valid threat models; technical complexity of vulnerability descriptions offers no protection when LLMs can abstract it away; and traditional security boundaries dissolve when the same tools that build software can be manipulated to break it. This represents a paradigm shift in software engineering -- we must redesign security practices for an era where exploitation requires only the ability to craft prompts, not understand code. Artifacts available at: https://anonymous.4open.science/r/From-Rookie-to-Attacker-D8B3.
format Preprint
id arxiv_https___arxiv_org_abs_2512_22753
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Rookie to Expert: Manipulating LLMs for Automated Vulnerability Exploitation in Enterprise Software
Diouf, Moustapha Awwalou
Diao, Maimouna Tamah
Olatunji, Iyiola Emmanuel
Kaboré, Abdoul Kader
Samhi, Jordan
Mendy, Gervais
Ouya, Samuel
Klein, Jacques
Bissyandé, Tegawendé F.
Software Engineering
LLMs democratize software engineering by enabling non-programmers to create applications, but this same accessibility fundamentally undermines security assumptions that have guided software engineering for decades. We show in this work how publicly available LLMs can be socially engineered to transform novices into capable attackers, challenging the foundational principle that exploitation requires technical expertise. To that end, we propose RSA (Role-assignment, Scenario-pretexting, and Action-solicitation), a pretexting strategy that manipulates LLMs into generating functional exploits despite their safety mechanisms. Testing against Odoo -- a widely used ERP platform, we evaluated five mainstream LLMs (GPT-4o, Gemini, Claude, Microsoft Copilot, and DeepSeek) and successfully exploited every tested CVE: at least one LLM produced a functional exploit for each within 3-5 prompting rounds. While prior work~\cite{jin2025good} found LLM-assisted attacks difficult and requiring manual effort, we demonstrate that this overhead can be eliminated entirely. Our findings invalidate core software engineering security principles: the distinction between technical and non-technical actors no longer provides valid threat models; technical complexity of vulnerability descriptions offers no protection when LLMs can abstract it away; and traditional security boundaries dissolve when the same tools that build software can be manipulated to break it. This represents a paradigm shift in software engineering -- we must redesign security practices for an era where exploitation requires only the ability to craft prompts, not understand code. Artifacts available at: https://anonymous.4open.science/r/From-Rookie-to-Attacker-D8B3.
title From Rookie to Expert: Manipulating LLMs for Automated Vulnerability Exploitation in Enterprise Software
topic Software Engineering
url https://arxiv.org/abs/2512.22753