meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 10th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 10 February 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Patch Tuesday; Dependency Confusion

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 10th, 2021 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.7

Well, Microsoft Patch Tuesday, of course, top of the news. Now, the number of vulnerabilities is pretty small. Microsoft fixed

0:24.1

56 vulnerabilities, 11 of which are rated critical. One has already been exploited, and

0:32.4

six were previously disclosed. But what's really kind of interesting with this particular patch set are three different

0:42.0

vulnerabilities that all have a CVSS score of 9.8.

0:48.0

The first one, Microsoft DNS server, another remote code execution vulnerability. Last one we had was back in July, if you remember.

0:58.0

And back then, well, we're sort of lucky was never really exploited.

1:03.0

I don't think there was ever sort of a full remote code execution exploit released.

1:08.0

Microsoft does rate exploitation likely for this vulnerability, CVE

1:14.9

2021-2478.

1:18.9

The second interesting vulnerability is a remote code execution in the TCP IP stack, and yes,

1:26.4

it affects source routing.

1:28.5

Source routing is one of those features you probably should block at your routers.

1:33.8

Don't really see it used for anything good these days or for the last 20 or so years.

1:40.0

Essentially, source routing allows the sender of a packet to define which routers a packet will be routed through, and many routers will outright just drop the packets or at least ignore it.

1:54.3

Windows will also ignore the option, but it will still return an ICMP message indicating that it denied the request, and apparently

2:03.0

there is a remote code execution here as the packet is being parsed.

2:09.8

The real workaround here is probably just not to allow any IPV4 options.

2:14.2

The official workaround is to block packets that have the source routing option set.

2:21.1

And then third, well, IPV6.

2:23.0

If IPV4 still has vulnerabilities, IPV6, of course, can't stand behind.

2:29.0

CVE 2021, 24094, which is patched here, does allow remote code execution via oddly fragmented packets.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.