ISC StormCast for Friday, March 13th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 March 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, March 13th, 2020 edition of the Sansanet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich. |
| 0:09.4 | And then I'm recording from Jacksonville, Florida. |
| 0:13.5 | Well, we got a patch from Microsoft. |
| 0:16.1 | Microsoft patched CVE 2020-0796. |
| 0:26.1 | That's the S&B version 3 compression issue just a couple days after it had its official patch Tuesday. So they must have fixed whatever sort of held |
| 0:32.2 | that patch back on the official patch Tuesday. Given that this is a remote code execution in the server |
| 0:41.9 | as well as in the client of current versions of Windows 10 and Windows server, this is something |
| 0:49.0 | that you should certainly patch. It is theoretically warmable, but it's nothing really to panic about. Now, we do |
| 0:58.3 | have a blog post that describes the flaw in details. There are proof of concert exploits out |
| 1:05.0 | there that will cause a blue screen of death, but that's about what we got so far, and it'll probably |
| 1:12.8 | be a while until there is more... |
| 1:16.2 | Probably it is a kernel stack overflow, and there are protections that are sort of built |
| 1:22.2 | in to Windows 10 and Windows server in recent versions that make exploitation of these vulnerabilities |
| 1:29.3 | quite difficult. |
| 1:31.3 | So why I don't say this will not get exploited, it'll probably be a while until we do see an exploit. |
| 1:37.3 | So try to get it patched. |
| 1:40.3 | I would say within the next couple weeks, the sooner the better. |
| 1:45.2 | There are also a couple scanners out there that you can use to check if you have any vulnerable |
| 1:50.0 | systems, but essentially if you have a recent version of Windows 10 Windows server, yes, |
| 1:55.1 | you're vulnerable, you should apply the patch. |
| 1:57.6 | If you don't want to apply the patch right now, then please apply the workaround, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

