4.9 • 696 Ratings
🗓️ 9 August 2017
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, August 9th, 2017 edition of the Sands and its Storm Center's Stormcast. My name's |
0:07.5 | Johannes Ulrich, and I'm recording from Jacksonville, Florida. Well, today was Microsoft's and |
0:14.6 | Adobe's Patch Tuesday, and we tried something new that we went back to something that looked more like these patch overview |
0:23.2 | tables that we did in the past. Now, we had to stop this for a couple of months because Microsoft's |
0:29.4 | patch process has changed too much, very no longer have bulletins, but trying to sort of re-immolate some of the features to be had back when |
0:41.5 | there were still bulletins. |
0:44.2 | Out of the 40 or so vulnerabilities being addressed here to have been known prior to this release, |
0:51.2 | seen some other sources that stated a third one was |
0:55.2 | priorly known and that was CVE 2017 8620. I just double-checked with |
1:03.6 | Microsoft's page about this vulnerability and they state that this third one has |
1:09.4 | not been publicly disclosed so I'll stick to a total of |
1:14.6 | two that have been public disclosed, but not yet exploited. |
1:19.5 | Overall, no real big surprises here. One curiosity, two of the vulnerabilities affect the Linux subsystem that has been recently included in Windows 10. |
1:33.4 | Now, one of them is just a denial of service vulnerability. |
1:36.8 | That's one of the two disclosed vulnerabilities. |
1:40.6 | And the second one is approach escalation vulnerability. Now most of the vulnerabilities do affect |
1:49.1 | in an explorer and Microsoft Edge in particular what you're seeing listed as scripting engine memory |
1:55.6 | corruption vulnerability. These are really Microsoft Edge vulnerabilities for newer operating systems. |
2:04.5 | And then we also got another critical remote code execution vulnerability in Windows |
2:09.7 | search. |
2:10.7 | This is something that has been addressed in two prior patches. |
2:15.6 | I believe June and July, we had Windows search patches. Some of them had |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.