August 2024 [Experts Analysis of Patch Tuesday]

Episode 10   Published August 13, 2024 14 minute watch

Summary

Ryan Braunstein steps in to host this episode alongside senior security engineer Seth Hoyt and technical product marketing manager David van Heerden to work through a month heavy on remote code execution flaws. The team focuses on the exploits worth prioritizing: the actively exploited SmartScreen prompt RCE (CVE-2024-38180), a Windows kernel elevation of privilege flaw (CVE-2024-38133), and a Windows Line Printer Daemon RCE (CVE-2024-38199) that puts unattended legacy print servers at risk. Their recurring point is that user education, consistent patching, and network segmentation matter more than any single fix, especially as Microsoft moves to restrict kernel access and push workloads out of the subsystem.