November 2024 [Cybersecurity Experts Discuss NTLM Spoofs, RCE Attacks, and Privilege Escalations]

Episode 13   Published November 12, 2024 8 minute watch

Summary

The Automox security team's top priority for November 2024 Patch Tuesday is an NTLM hash disclosure spoofing flaw already exploited in the wild, where a single phished click lets an attacker authenticate as the user. It leads another month heavy on remote code execution. The team also breaks down CVE-2024-5533, a Defender for Endpoint RCE that turns the endpoint's own defense tool against it, and CVE-2024-49039, a Windows Task Scheduler privilege escalation with functional exploit code Microsoft has confirmed exists.