4.9 • 696 Ratings
🗓️ 20 July 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, July 20th, 2021 edition of the Sansonet Storm Center's Stormcast. My name's Johannes Ulrich. And today I'm recording from Jacksonville, Florida. |
0:13.6 | Brent Nightmare is the vulnerability. It keeps on giving. We have now yet another CVE that's being tracked for Print Nightmare, and that's CVE |
0:24.3 | 2021, 34, 481. I briefly, I think, mentioned it on Monday. This is the local privilege escalation, |
0:34.1 | so it does allow a local user to obtain system level privileges. |
0:39.2 | It's not exploitable remotely like the prior vulnerability, which of course still makes it a |
0:45.7 | problem but the lesser problem than the other print nightmares. |
0:50.5 | Not a lot of details here other than the CVE number and the scope of the vulnerability to mitigate the vulnerability. |
0:58.3 | For now, your only choice is to disable the print spooler service. |
1:04.4 | And Apple today released updates for iOS, watchOS, TVOS, as well as for Safari, but the Safari update was only released for |
1:14.4 | MacOS, Catalina and Mojave. |
1:18.1 | So far, Apple has embargoed any vulnerability details, but, well, it can be assumed that |
1:24.9 | there are multiple vulnerabilities that are being addressed by these updates. |
1:29.2 | In particular, the iOS update is something you probably do want to apply. |
1:34.5 | Now, Safari is kind of interesting. |
1:36.5 | Typically, Apple is releasing Safari for these older operating system, |
1:41.4 | and then an update for the latest operating system, which would be |
1:45.8 | macOS bixir at this point. However, this hasn't happened yet. Apple today released a second |
1:52.9 | release candidate for the next version of macOS bixir. Also a little bit unusual to have two |
1:59.9 | release candidates. Likely something sort of, you know, |
2:03.2 | came up in the last sort of sanity checks before they got ready to release this. I would expect |
2:11.1 | an update for macOS to be delivered maybe on Tuesday today or later this week. At that point, we probably will also |
2:20.2 | get more details about these vulnerabilities. Apple usually holds them back if there is a lot of |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.