ISC StormCast for Wednesday, August 10th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 August 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, August 10th, 2022 edition of the Sands and the Internet Storm Center's Stormcast. |
| 0:08.7 | My name is Johannes Ulrich, and then I am again recording from Jacksonville, Florida. |
| 0:14.8 | Top of the news today, no surprise, Microsoft's patch Tuesday, we got patches for a total of 141 vulnerabilities, |
| 0:24.2 | which does include the chromium patches for Microsoft Edge, which were released earlier. |
| 0:31.7 | 17 of these vulnerabilities are critical and two have already been disclosed. |
| 0:36.2 | Now, there's also one vulnerability CVE 22-34-713 |
| 0:42.5 | that has already been exploited. This vulnerability is actually affecting sort of an good old friend. |
| 0:50.0 | It's a patch for a path traversal vulnerability in Microsoft Windows Support Diagnostic tool or MSDT, |
| 1:00.7 | which has caused a lot of problems, of course, over the last two years or so, and this new |
| 1:06.5 | variant of the patch traversal issue has been in some form around for two years, has been |
| 1:12.9 | sort of rediscovered back in June, and also now has a nice kind of name, the Dog Walk vulnerability. |
| 1:21.6 | This vulnerability, as well as a second MSDT vulnerability, are both rated as important, not critical, exploitation would |
| 1:29.5 | require some user interaction, which causes the lower rating. |
| 1:34.9 | But for Microsoft Exchange Server, we do have three vulnerabilities that are privileged |
| 1:41.2 | escalation vulnerabilities, but still rated critical. |
| 1:45.3 | They're affecting Exchange Server 2013, 16 and 19, |
| 1:50.0 | but to mitigate these issues, just applying the patch is not sufficient. |
| 1:55.3 | In addition, you need to enable Windows extended protection on your exchange server. Microsoft released a blog post |
| 2:05.0 | about it with detail. Extended protection is mainly meant to prevent machine in the middle |
| 2:10.4 | attacks. Microsoft made a script available to make it easier to enable extended protection |
| 2:17.1 | on your servers. |
| 2:19.1 | But as the blog warns, please read up first and make sure nothing breaks as you enable it. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

