December 2024 [Merry FixMas and a Happy Patched Year]

Episode 14   Published December 10, 2024 11 minute watch

Summary

December 2024 Patch Tuesday ships a full slate of vulnerabilities, and three stand out this month. Seth Hoyt covers CVE-2024-49093, a ReFS elevation-of-privilege flaw that lets an attacker escape a low-privilege app container and move east-west across Windows servers. Ryan breaks down CVE-2024-49132, a use-after-free remote code execution bug in Remote Desktop Services. Henry flags CVE-2024-49138, a Common Log File System driver elevation-of-privilege vulnerability that is already being exploited in the wild and was credited to CrowdStrike.