April 2025: [Remote Desktop Roulette, CLFS Exploits, and macOS Vulns]

Episode 18   Published April 8, 2025 11 minute watch

Summary

April 2025 was a light month for Microsoft that still carried two use-after-free risks worth acting on. CVE-2025-27480 is a Windows Remote Desktop Gateway remote code execution flaw that needs no login and no user interaction. CVE-2025-29824, a Common Log File System driver privilege escalation, was the only CVE on the list already exploited in the wild. The heavier load came from Apple: macOS Sequoia 15.4 patched 131 CVEs, reportedly a record for the platform, including CVE-2025-24243, an audio-component flaw that runs arbitrary code from a maliciously crafted file.