ISC StormCast for Thursday, October 31st 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 31 October 2019
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, October 31st, 2019 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:09.8 | I'm recording from Jacksonville, Florida. |
| 0:13.9 | Well, we finally got some details about the security content of this week's Apple updates so we had updates for iOS watch OS |
| 0:24.7 | TV OS but also for macOS Catalina and for Safari as well as for iCloud |
| 0:32.7 | for Windows and iTunes for Windows let Let's start with MacOS. |
| 0:39.3 | A number of privilege escalation vulnerabilities are being addressed here as usual. |
| 0:44.3 | There is very little detail from Apple, of course, here to go by. |
| 0:49.3 | A couple vulnerabilities that sort of stuck out as being somewhat interesting. |
| 0:53.3 | For example, the first one, |
| 0:55.8 | a vulnerability in accounts that allows a remote attacker to leak memory, which is kind of |
| 1:04.4 | odd as a vulnerability in this particular subsystem. A number of code execution vulnerabilities in, for example, |
| 1:13.6 | audio players, so parsing malicious audio file would trigger this. |
| 1:19.6 | Also interesting, malicious application may be able to gain root privileges via manpages. So not sure if the user would have to install it |
| 1:30.3 | and then by installing demand pages this would be triggered or by reviewing an arbitrary man |
| 1:36.5 | page, this particular exploit would be triggered. Again, very little detail here on what the |
| 1:43.9 | actual exploit mechanism is. Now, the |
| 1:47.0 | vulnerabilities being addressed in the iOS and iPad OS updates are pretty much a copy of what we |
| 1:53.4 | have for macOS, but there are also, I think it's 11 different vulnerabilities that are fixed in WebKit. Of course, these |
| 2:03.1 | vulnerabilities are addressed via the separate Safari update for Mac OS. As far as iTunes and |
| 2:12.1 | ICloud for Windows Go, the bulk of the vulnerabilities being addressed are again web kit issues. |
| 2:19.3 | There is one vulnerability that's common to all these Windows patches that Apple released, |
| 2:26.7 | and that's a graphics driver vulnerability that may lead to object code execution with |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

