meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, August 12th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 August 2020

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. vBulletin 0 Day; MSFT Patches; Adobe Patches; Citrix Endpoint Mgmt Update

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, August 12th, 2020 edition of the Sandtonet Storm Center's Stormcast.

0:07.2

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:12.8

I want to deviate a little bit from the usual patch Tuesday podcast by not starting with Microsoft's patches,

0:19.4

but instead highlighting vulnerability in the Bulletin.

0:24.4

The Bulletin is a commercial bulletin board system written in PHP, and it has a rather intricate

0:31.2

template system, which has been the source of some critical vulnerabilities in the past. Last September, the bulletin

0:41.0

fixed CVE 2019 16759, which was a code injection vulnerability, and apparently this patch was

0:50.9

not complete, which did allow for a bypass of the patch, and details were

0:57.1

published on Sunday by a researcher who calls himself SinoFex. So yes, the bulletin is again

1:06.1

vulnerable to code injection attack. Attackers are able to execute arbitrary PHP code on the server.

1:15.7

The exploit is trivial, and an example, really more than just proof of concept, has been

1:22.5

released as part of this blog post.

1:26.5

So I would expect exploitation to already be underway.

1:31.3

The blog post also mentions a possible workaround, that essentially means disable

1:37.3

PHP, static HTML, and ad module rendering. No idea what it'll break, but certainly worth a try. So well, let's talk about

1:49.0

Microsoft vulnerabilities next. Microsoft patched 120 vulnerabilities for patch Tuesday. Two of these

1:56.9

vulnerabilities have already been exploited. CVE 2020 1464. This is a Windows spoofing

2:05.8

vulnerability. What it means is that signatures of files may incorrectly be validated and an attacker

2:15.1

could use that to bypass some security features by, for example, loading inappropriately signed files.

2:24.7

The second vulnerability is probably more severe.

2:27.7

That's a remote code execution that's affecting Internet Explorer.

2:32.1

It's part of the scripting engine that's vulnerable here, and that's CVE 2020-1380.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.