Light

Episode #895 Quiz

After 20 Years in GCHQ
Date: 2022-11-01 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Microsoft finally updated the Windows vulnerable driver blocklist, usable via WDAC policies and SiPolicy.p7b, to block BYOVD abuse, though it normally refreshes only with major releases. The episode also covered Microsoft’s CVE omission policy, OpenSSL 3.0.7’s critical flaw, a Windows TCP/IP RCE, malicious GitHub PoCs, and SQLite’s 22-year string-formatting bug.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what was the documented reason Microsoft gave for why the vulnerable driver blocklist had not been broadly updated for older Windows versions until the October 2022 preview release?
Question 2: What did Microsoft say Windows users could do if they wanted the most up-to-date vulnerable driver blocklist without waiting for the next major Windows release?
Question 3: What was the main technical condition that made the Windows TCP/IP remote code execution flaw discussed in the episode largely unlikely to be exploitable in practice?
Question 4: How many malicious GitHub proof-of-concept repositories did the Leiden University researchers report finding, out of how many total repositories studied?
Question 5: According to the episode’s description of the SQLite 'Stranger Strings' flaw, under what compilation condition was arbitrary code execution confirmed to be possible?
Cancel