meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 11th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 December 2024

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Patch Tuesday; Ivanti Vuln; Visual Studio Code Tunnels; Mitigating NTLM Relay Attacks

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, December 11th,

0:03.5

2024 edition of the Sands and at Storms,

0:07.0

on us Stormcast, my name is Johannes Ulrich,

0:10.0

and then I'm recording from Jacksonville, Florida.

0:13.7

It's Microsoft Patch Tuesday, so of course,

0:16.1

let's start with what Microsoft had to offer.

0:19.5

Today we got patches for 71 different vulnerabilities,

0:23.6

which doesn't consider some of the chromium vulnerabilities affecting Microsoft Edge.

0:30.6

16 of these vulnerabilities were considered critical, and we do have one vulnerability that already had been exploited.

0:40.0

This vulnerability is yet another privilege escalation vulnerability in the Windows Common

0:45.9

Log File system driver. This subsystem did have a number of similar vulnerabilities in the

0:53.1

past, given that it's already being exploited.

0:56.6

It's certainly significant.

0:59.3

Secondly, we do have nine different critical vulnerability, so that's more than half of the critical

1:05.5

vulnerabilities this Tuesday in the Windows Remote Desktop Services. Exposing remote desktop services to the Internet,

1:14.9

of course, is a vulnerability in itself, even not considering these vulnerabilities that

1:21.1

were being addressed today. An exploit here may, however, lead to a remote code execution.

1:27.7

So, well, yet another reason not to expose your remote desktop services.

1:33.0

Of course, this could still be used for lateral movement.

1:37.2

And talking about lateral movement, we do have two remote code execution vulnerabilities in LDAB that are also considered critical,

1:46.2

one of them with a CFSS score of 9.8, and then sort of a blast from the past.

1:52.6

If you remember the plaster warm, yet another remote code execution vulnerability in the LSAS service.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.