ISC StormCast for Wednesday, December 14th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 December 2016
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, December 14th, 2016 edition of the Sandternut Storm Center's |
| 0:06.5 | Stormcast. My name is Johannes Ulrich, and I'm recording from Washington, D.C. Well, today, of course, Microsoft |
| 0:13.6 | patched Tuesday. We got 11 different bulletins from Microsoft plus one from Adobe for Flash that was also included by Microsoft. |
| 0:23.4 | The Adobe one is of course critical as usual. In addition, we had five of the Microsoft |
| 0:30.0 | bulletins that are rated critical. We did rate the bulletins for Internet Explorer and Microsoft |
| 0:37.3 | Edge as critical because one of the vulnerabilities is already publicly known and may lead to arbitrary code execution. |
| 0:48.3 | This particular vulnerability is CVE 2016-702 and it is a memory corruption vulnerability in the scripting engine. While these |
| 1:00.3 | vulnerabilities are publicly disclosed there is currently according to Microsoft no exploitation |
| 1:06.9 | reported for these issues. A third bulletin included a publicly disclosed vulnerability, and that's the bulletin for the |
| 1:16.3 | dot net framework, MS16, 155. |
| 1:20.1 | We didn't rate that as a patch now because it's just an information disclosure vulnerability. |
| 1:27.4 | Other net really nothing too |
| 1:29.0 | terribly exciting, tons of vulnerabilities being patched in office. That's actually the bulletin |
| 1:35.2 | with the most vulnerabilities assigned to it, MS-16148. But none of these vulnerabilities are |
| 1:43.0 | publicly disclosed or have been exploited in the wild. |
| 1:47.7 | So as far as patch priority goes, start with the patches for InExplorer, Edge, and then of course |
| 1:55.4 | Flash, and then continue with the remainder in whatever order you see fit. |
| 2:01.6 | And well, Microsoft wasn't alone today. |
| 2:03.6 | Apple continued its updates. |
| 2:06.6 | Yesterday we saw iOS, TVOS, and watchOS updates. |
| 2:11.6 | The watchOS update was actually removed again because it caused some issues with some watches. |
| 2:20.5 | Now, today we also got an update for macOS Sierra. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

