Light

Episode #867 Quiz

A Critical Windows RPC RCE
Date: 2022-04-19 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Chrome’s third 2022 zero-day was a V8 type-confusion flaw fixed in desktop Chrome 100.0.4896.127. Microsoft’s 128 patches included 47 RCEs and 47 privilege escalations, with a 9.8 RPC runtime integer-overflow bug enabling heap overflow and zero-click worm potential. Mitigation: patch immediately, restrict exposure, and avoid public SMB/RPC access.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, which Windows component contained the actively exploited zero-day privilege escalation that was reported by both the NSA and CrowdStrike?
Question 2: What did the episode say was the key security weakness in the Elementor WordPress plugin version 3.6.0?
Question 3: In the discussion of Apache Struts, what current version did Steve say users should immediately upgrade to or beyond?
Question 4: What did Akamai identify as the underlying flaw mechanism in CVE-2022-26809 after diffing the patched Windows RPC runtime library?
Question 5: Which transport did the episode explicitly note as the most common way RPC was carried for this Windows vulnerability?
Cancel