meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 6th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 6 November 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Possible Exchange Flaws; Sriped Fly Botnet; Send My

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, and welcome to the Monday, November 6, 2020,

0:04.1

edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich,

0:10.0

and today I'm recording from Jacksonville, Florida.

0:14.0

The CRD Initiative on Friday released details regarding four vulnerabilities in Exchange server that so far according to the

0:25.0

Serra Day initiative have not been patched. Now, there is a little bit of controversy here as to,

0:30.8

first of all, how severe these vulnerabilities are and whether or not they are exploitable

0:36.9

in current issues of the exchange server.

0:41.7

The first one that is labeled here as CDI 231578.

0:48.2

It's a remote code execution flaw, and it allows the execution of arbitrary code as system.

0:55.5

Now Microsoft stated in a response here that customers who have applied the August

1:00.8

security update are already protected, so in that way it would no longer be exploitable.

1:08.1

The remaining three vulnerabilities are all very similar. They're essentially

1:12.4

URI validation vulnerabilities where an attacker is able to trick the system into, for

1:20.0

example, downloading data from a URI that, well, the attacker isn't supposed to be able

1:26.1

to download data from.

1:28.2

At least sort of that's a description from CDI.

1:32.0

Microsoft's response, on the other hand, states that these vulnerabilities do not really

1:37.8

present privilege escalation.

1:40.2

They just execute functionality as the user logged in.

1:46.1

So it's not that you would be able to download data from another user or escalate privileges,

1:51.8

basically doing things that you weren't supposed to be doing.

1:55.2

And yes, you do need credentials.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.