February 2025: [Experts Break Down Zero-Days, 7-Zip Vulnerabilities, and More]

Episode 16   Published February 11, 2025 20 minute watch

Summary

February 2025's patches share a pattern: the bar to exploit them keeps dropping, often to a ready-made GitHub proof of concept. Henry opens with CVE-2025-21293, an Active Directory elevation of privilege that now has a live proof of concept abusing the little-known Network Configuration Operators security group. He then covers CVE-2025-21418, an actively exploited WinSock (AFD.sys) zero-day that reaches back to Server 2008. Ryan and Brian cover a 7-Zip Mark of the Web bypass and an Apple AirPlay flaw. The 7-Zip, AirPlay, and Disk Cleanup bugs all target trusted, low-suspicion surfaces. The hosts note that behavioral, non-Windows EDR may catch the 7-Zip bypass that Defender misses.