ISC StormCast for Tuesday, October 20th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 October 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday in October 20, 2020 edition of the Santernet Storm Center's Stormcast. |
| 0:08.0 | My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida. |
| 0:14.0 | Interestingly, after Microsoft had its big patch Tuesday on, well, last Tuesday, we got two additional patches. Now, the |
| 0:24.3 | advisories are dated for October 15th, so that would be last Thursday. I just noticed them, |
| 0:31.2 | and both vulnerabilities don't really look like they're critical enough to sort of warrant an out-of-band |
| 0:39.3 | or emergency patch, but in particular, the first one, CVE 2020-17-023 sounds interesting. It's a remote |
| 0:49.8 | code execution vulnerability in Visual Studio Code. Now, Visual Studio Code is an editor that a lot of |
| 0:58.8 | developers like and if you open a malicious JSON file with this editor, remote code |
| 1:06.5 | execution may happen. Given that this tool is used by developers who are somewhat a target |
| 1:13.9 | and that for a developer it would be perfectly normal to open a JSON file in this editor, |
| 1:21.3 | I do think that this vulnerability certainly should be addressed and patched quickly. |
| 1:28.3 | The second one is a little bit more run-off the mill, I would say. |
| 1:32.3 | It's a remote code execution warby again, but it's in Microsoft Windows codec |
| 1:38.3 | libraries. |
| 1:40.3 | And given that we have a lot of these vulnerabilities typically, this is not yet exploited. |
| 1:48.0 | It has not been publicly disclosed. |
| 1:50.1 | I'm not really sure why Microsoft sort of published a special out-of-band patch for this vulnerability. |
| 1:58.4 | It does affect Windows 10 only according to the advisory. |
| 2:04.6 | Now if Microsoft release a special patch, then Adobe has to release one, two, and we do have |
| 2:12.6 | a patch for the Magento e-commerce software. |
| 2:18.3 | Given that this has been a big target in the past, |
| 2:22.3 | probably worthwhile paying attention here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

