ISC StormCast for Wednesday, April 10th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 April 2024
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, April 10, 2024 edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich and today I'm recording from London, England. |
| 0:14.6 | It's Microsoft Patch Tuesday and well with that, let's get started talking about some of the vulnerabilities Microsoft addressed |
| 0:23.4 | in today's update. There are a total of 157 vulnerabilities being addressed this month in total. |
| 0:31.5 | Now, seven of them were known before today. These are chromium vulnerabilities that affected Microsoft Edge. Out of the remaining |
| 0:40.5 | 150 vulnerabilities, we have one important vulnerability that has already been exploited and has been |
| 0:48.8 | made public before today. It's a proxy driver spoofing vulnerability. I haven't had a lot of luck finding details, |
| 0:57.5 | even though it is labeled as being known and being made public before today. But that may |
| 1:03.1 | just be a matter of not finding the right CVE, or maybe the CVE number was not attached to |
| 1:08.8 | some of the earlier reports. |
| 1:11.3 | Now, we only got three critical vulnerabilities this month, and all critical |
| 1:17.9 | vulnerabilities are affecting Microsoft Defender for IoT, and they represent a remote |
| 1:25.8 | code execution vulnerability. |
| 1:28.3 | Another little odd thing is that we got about 40 |
| 1:32.3 | and it's a little bit hard to count them all. |
| 1:34.3 | Important vulnerability that all affect Microsoft OLE drivers |
| 1:39.3 | for SQL servers. |
| 1:41.3 | Now, when I read this first, it's a remote code execution vulnerability. |
| 1:45.8 | I was a little bit surprised that it's rated as important, not critical. |
| 1:49.0 | However, that rating makes sense when you're looking at some of the details. |
| 1:54.0 | This does not affect the server at all. |
| 1:56.3 | It affects the clients. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

