ISC StormCast for Wednesday, December 14th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 December 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, December 14, 2020 edition of the Sandtonet Storm Center's Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
| 0:14.9 | Well, quite the patch Tuesday today and a little spoiler alert here, but we got three different companies |
| 0:23.3 | patching vulnerabilities that are already being exploited in the wild. |
| 0:28.6 | So let's start with Microsoft, of course, who sort of invented, I guess, patch Tuesday. |
| 0:34.8 | And for the last patch Tuesday of the year, we got patches for 74 vulnerabilities, |
| 0:41.0 | which includes the chromium fixes for Microsoft Edge. Not everybody sort of considers them |
| 0:47.6 | Microsoft patches. And seven of the vulnerabilities that were patched are rated as critical. |
| 0:55.9 | One has been previously disclosed and one is already being exploited. |
| 1:00.8 | Now, the already exploited vulnerability is a problem with the Windows smart screen feature. |
| 1:07.5 | That's something I've mentioned a few times before and some of its weaknesses |
| 1:11.5 | in Windows. The problem here is this mark of the web, this extended data stream that's |
| 1:19.1 | being added to mark files that were downloaded from the web to treat them differently if |
| 1:25.1 | the user then attempts to open these files. |
| 1:29.1 | Not technically a vulnerability, but something that's included as an advisory in this update |
| 1:36.6 | is issues with drivers that are assigned using Microsoft's developer program. |
| 1:43.6 | Apparently, some of the certificates very used for lateral movement by the Cuba Ransomare, |
| 1:51.2 | and Microsoft now revoked those certificates. |
| 1:56.5 | And then we got one vulnerability here that was publicly known but hasn't apparently been used |
| 2:03.3 | in any exploit yet, and that's DirectX Graphics kernel elevation of privilege vulnerability. |
| 2:10.7 | A couple other noteworthy vulnerabilities here. |
| 2:14.4 | There is a remote code execution vulnerability in the dot net framework. |
| 2:18.9 | Less likely to be exploited according to Microsoft, but a CVSS score of 8.8. And then we do have |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

