ISC StormCast for Thursday, October 12th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 October 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, October 12, 2023 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:13.6 | Well, today as usually is a little bit a patch Tuesday cleanup episode. |
| 0:17.9 | Let's start out with new exploits. Microsoft stated in |
| 0:23.3 | relation has confirmed active exploitation of CVE 2023-22515. This vulnerability, which |
| 0:33.1 | was patched about a week ago, is apparently already actively being exploited. It does allow |
| 0:40.0 | an attacker to add an arbitrary administrative account to Atlacians, Confluence, Data Center, and |
| 0:47.4 | server. I've seen an exploit post on Twitter. No idea if it's actually correct but looks plausible. |
| 0:56.2 | Given that it fit in a tweet and can be run with a simple curl comment, it's a pretty |
| 1:02.8 | trivial exploit. |
| 1:04.6 | So I hope it's a little bit more complicated than that. |
| 1:07.1 | But definitely the exploit is out and available and being used. |
| 1:14.5 | And yes, we did get an update to curl today fixing a security vulnerability. |
| 1:20.8 | However, the security vulnerability didn't turn out to be all that big of a deal. |
| 1:26.8 | Now, it is a heap-based buffer overflow, which of course means that there is a potential |
| 1:32.7 | for code execution. |
| 1:34.7 | But in order to actually trigger the vulnerability, an attacker has to be able to feed an oversized |
| 1:42.0 | URL to curl that is then using a SOX5 proxy. |
| 1:47.7 | Given that most curl instances do not connect to a SOX5 proxy and that you definitely should |
| 1:56.9 | probably verify that you have a valid host name before you just pass a URL to curl. |
| 2:03.2 | The exploitation is likely limited to a very limited number of sort of edge cases. |
| 2:10.4 | So nothing to worry about too much. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

