4.9 • 696 Ratings
🗓️ 9 April 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, April 9th, |
0:03.2 | 2025 edition of the Sands and the Storm Center's Stormcast. |
0:08.3 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:13.1 | Well, of course, it's Patch Tuesday today, so we have to start with Microsoft Patches. |
0:18.7 | We do have sort of an average Patch Tuesday. Renato, who did our diary today, |
0:24.3 | counted in 125 vulnerabilities. I've seen others, quote, 134 vulnerabilities. It typically depends on |
0:31.7 | whether or not you count the chromium vulnerabilities that apply to Microsoft Edge or not. |
0:38.7 | But either way, let's look at some of the interesting vulnerabilities that are sort of worth noting. |
0:45.7 | And to start out, we got sort of a column a friend of the show, the log file system driver. |
0:52.6 | This is a Windows component that has led to at least five Saturday vulnerabilities over the |
0:59.2 | last couple years. |
1:01.0 | And yes, we do have another ProH escalation vulnerability here that is already being exploited |
1:07.1 | and apparently being exploited by ransomware actors as well. |
1:11.6 | So not just one of those state actor style vulnerabilities. |
1:16.2 | Now, why is this component continuing to be the source of so many warn abilities? |
1:22.4 | Pretty straightforward reasoning behind this is it is a kernel driver, so it runs with |
1:27.4 | colonel privileges. It must run kernel driver, so it runs with kernel privileges. |
1:28.8 | It must run with kernel privileges, well, in some ways, because it has to read all the different |
1:35.3 | logs that it is parsing. And then, of course, it has to parse those logs, and logs sometimes |
1:42.5 | do contain, well, hostile content. And that's sort of the |
1:47.2 | reason here yet again, where a problem in the log parser is being exploited to then elevate |
1:53.9 | privileges, essentially execute code as the driver, which then gets you full system access. So that story just keeps repeating. |
... |
Transcript will be available on the free plan in 5 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.