ISC StormCast for Monday, January 20th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 January 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, January 20th, 2020 edition of the Sandcent, Storm Center's Stormcast. |
| 0:07.5 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.5 | Well, on Friday, you may have been too busy dealing with Microsoft's patch Tuesday, all of those good remote desktop gateway issues, |
| 0:24.8 | and of course the signature problem to notice that Microsoft published another security advisory |
| 0:33.2 | with warning that there is a memory corruption issue in Microsoft's scripting engine that's |
| 0:42.1 | currently actively being exploited. |
| 0:45.4 | Microsoft scripting engine, of course, that's JavaScript, and with that, browsers are affected |
| 0:51.6 | by this according to the advisory. |
| 0:55.2 | Everything going back to Internet Explorer 9 on Windows Server 2008 is affected. |
| 1:01.8 | I don't see Windows 7 listed here, but remember this bulletin was released after the Windows |
| 1:09.8 | 7 expiration date. |
| 1:11.6 | So no surprise to not have it listed here and I would almost expect it to be vulnerable. |
| 1:18.6 | Now Microsoft's workaround here is to essentially remove access to JScript.DL. |
| 1:24.6 | When I saw this first I thought, well, that's not really going to work in any |
| 1:29.5 | practical system. Sounds like you're turning off JavaScript. Well, it turns out that's actually |
| 1:35.7 | not quite true. The affected browsers usually use J-Crypt9. DLL, which is not affected, not JScript.t.l. |
| 1:47.4 | So J-Script. dlll is only used in certain circumstances. |
| 1:51.9 | It's a little bit hard to predict what's going to happen if you do disable J-script.tl, but |
| 1:57.4 | well, it's always a lot of fun to debug things like this on production system so just go ahead |
| 2:04.6 | And of course the other vulnerability that we are tracking is CVE 2020 0601 or curveball now a couple of people reported that |
| 2:15.9 | Virus Total shows a number of no actual malware being |
| 2:21.1 | delivered with fake signatures. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

