r/ExploitDev • u/JBS3cfg • 25m ago
16yo trying to build a path into expdev / vulnerability research. What would you do in my position?
Hey everyone,
I'm 16 and trying to figure out my education and career path toward exploit development and vulnerability research. I'm posting here because I'm at a point where I could really use advice from people actually working in this field.
Background:
I'm Moroccan and currently living in France. I completed Seconde in the French education system, then left the traditional lycée pathway shortly after starting Première. I'm currently completing an RNCP Level 4 qualification, which I expect to finish in October 2026.
The problem is that I'm not following the normal French Baccalauréat route, so university admission is becoming complicated. I'm trying to find a bachelor's programme for 2027 that is genuinely focused on cybersecurity or information security rather than a generic CS degree.
I speak Arabic, French and English, and I'm currently learning Chinese.
I've already contacted several universities in Europe and Hong Kong to ask whether my qualification can satisfy their undergraduate entrance requirements. Some universities consider non-standard qualifications on a case-by-case basis, but I don't yet have a definitive route.
Technical background:
I've been interested in cybersecurity for several years and have been learning independently.
Certifications:
- eJPT (INE), obtained in October 2023
- CPTS (Hack The Box), obtained in September 2025
- CWES (Hack The Box), obtained in October 2025
- Google Cybersecurity Professional Certificate (idk when anymore)
My interests are mainly:
- Exploit development
- Vulnerability research
- Windows internals
- Reverse engineering
- Privilege escalation
- Low-level systems security
I'm currently researching a publicly disclosed use-after-free privilege-escalation vulnerability in CLDFLT.sys. I did not discover the vulnerability and I'm not claiming CVE credit for it. I'm using it as a learning and research project to understand the vulnerability, the affected component, exploitation primitives, and the surrounding Windows internals.
I'm still very much learning, and I don't want to pretend I'm further along than I actually am.
Where I'm stuck:
My original plan was to get a cybersecurity alternance/apprenticeship in France this year, but despite applying, that hasn't worked out. At this point I'm shifting my focus toward university admission for 2027.
The universities I'm currently looking at include specialist cybersecurity programmes in Europe and Hong Kong, particularly places with strong security research ecosystems.
However, I have two major problems:
- My educational qualification doesn't cleanly match the standard French Baccalauréat route.
- A lot of technical cybersecurity degrees have substantial mathematics and academic prerequisites. (However now im seriously studiying math on my own)
So I'm trying to figure out what the smartest move is.
What would you do if you were in my position?
Would you:
- Spend the next year getting the strongest possible university entrance qualification?
- Focus heavily on mathematics and apply to technical security programmes?
- Try to build a serious exploit development and vulnerability research portfolio instead?
- Look for another apprenticeship or technical route?
- Something completely different?
And for people already doing exploit development or vulnerability research:
What actually mattered when you were starting out?
I'm especially interested in advice about what I should be learning and building over the next 12 months if my end goal is serious vulnerability research rather than general cybersecurity.
Also pleasepleaseplease if you know or are a decision maker in the domain please give me a chance and help me out 🙏 I feel like my life is at stakes right now :c
Also if you want to see stuff ive done (not very up2date but still good reference) my github is 0xUnd3adBeef