Light

Episode #1023 Quiz

Preventing Windows Sandbox Abuse
Date: 2025-04-29 | Length: 2.25 hrs | Episode page at twit.tv

About this episode

Windows' April 2025 Patch Tuesday introduced an empty inetpub folder essential for CVE-2025-21204 mitigation, improperly fixed by Microsoft, requiring IIS installation to restore if deleted. This fix enabled a denial-of-service via junction points stopping Windows Updates.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What is the primary reason Microsoft requires the inetpub directory to exist on Windows 11 systems after the April 2025 Patch Tuesday update?
Question 2: How can malware abuse the Windows Sandbox feature on Windows 10 and 11?
Question 3: What mitigation strategies were suggested to prevent Windows Sandbox abuse by unauthorized users?
Question 4: According to the episode, what is a key limitation of Windows Sandbox related to OS compromise scenarios?
Question 5: What key issue did Kevin Beaumont discover related to the inetpub directory and the Windows servicing stack patch for CVE-2025-21204?
Cancel