meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 12th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 12 December 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. #MSFT Patch Tuesday; #Adbode Patch; Certificate Authority DNS Spoofing Weakness

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 12, 2018 edition of the Sansonet Storm Center's Stormcast.

0:06.7

My name is Johannes Ulrich.

0:08.2

And then I'm recording from Jacksonville, Florida.

0:11.7

And well, it's a patched Tuesday, so let's start with this Microsoft patched 39 vulnerabilities, 10 of which are rated critical.

0:22.9

Now, one of the critical vulnerabilities was Adobe's Flash Update, which was already

0:28.5

released last week, so this just rolls this into the normal monthly update cycle.

0:35.1

In addition to this Flash War on flash vulnerability, which was apparently used

0:39.1

against some hospital in Russia, Microsoft also patched a Windows kernel elevation of bridge

0:46.1

vulnerability that also was already used in the wild. In addition, there was a dot-net framework

0:54.0

denial of service vulnerability that also was already

0:57.2

disclosed but hasn't really been seen in active exploits yet.

1:02.8

Now the big winner here as usual is the chakra scripting engine.

1:08.1

It accounts for five of the critical vulnerabilities. The Chakra scripting engine is, of course,

1:14.6

Microsoft scripting engine that you find in browsers. So all of these vulnerabilities are accessible

1:21.6

via malicious content in your web browser. The one vulnerability I don't really have seen much about, but I think that you should

1:31.0

probably pay attention to is the Windows DNS server heap overflow vulnerability.

1:35.4

That's CVE 2018-8626.

1:39.9

Microsoft rate is critical with a CVSS score of 9.8, but considers exploitation less likely.

1:48.1

Now, as far as patching priorities go, well, I would certainly prioritize all of these browser

1:54.4

and scripting vulnerabilities, and like I said, watch your DNS servers probably expedite that particular patch a little bit.

2:04.7

Now with Adobe already releasing this flash update last week, they only had Adobe Acrobat

2:10.6

and Reader Patch for today.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.