ISC StormCast for Wednesday, April 15th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 April 2020
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, April 15th, 2020 edition of the Sansanet Storm Center's |
| 0:06.7 | Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
| 0:13.7 | Well, it's patched. Tuesday. Microsoft released updates fixing 113 vulnerabilities today. |
| 0:21.5 | A little bit more interesting than last month in the sense that we do have three vulnerabilities |
| 0:27.3 | that are being patched here that already had been exploited in the wild. |
| 0:33.3 | Two of them were reported by Google's Project Zero and these two vulnerabilities, that's |
| 0:40.0 | CVE 2020, 1020, as well as 0938. |
| 0:44.6 | These are remote code execution vulnerabilities in the Adobe Fond Manager Library. |
| 0:49.5 | So similar to the vulnerability that sort of caused so much excitement last month, the font library vulnerability |
| 0:58.1 | that then had to be patched a couple days after the official patch Tuesday. The third one, |
| 1:04.9 | well, a yet another scripting vulnerability in Internet Explorer 2020 0968. |
| 1:13.6 | Now, two of these vulnerabilities had been disclosed publicly in the past. |
| 1:18.6 | The first one, the Adobe vulnerability and then CVE 2020 0935 also has already been publicly disclosed. |
| 1:29.9 | CVE 2020 0935 is one drive approach escalation vulnerability, so not quite as critical as these remote code execution vulnerabilities, which is why it only got a rating of important. Adobe released updates |
| 1:47.1 | for three different products today, Adobe Cold Fusion, Adobe After Effects, and Adobe Digital |
| 1:53.7 | Editions. The one that I always sort of look at closer are the Cold Fusion vulnerabilities. |
| 1:59.5 | They have caused a lot of problems in the past. This set |
| 2:03.4 | doesn't look that severe. The severity is only rated as important. It's mostly denial of |
| 2:10.4 | service and privilege escalation vulnerability. There is a system file structure disclosure |
| 2:17.4 | vulnerability, which again could |
| 2:20.3 | leak information and help attacker exploit other vulnerabilities, but overall nothing really |
| 2:26.2 | terribly critical here. And Microsoft also announced that it will extend the end of life |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

