meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 12th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 12 February 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft/Adobe Patches; Ransomware Abuses Vulnerable Driver

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 12, 2020 edition of the Sandcent Storm Center's Stormcast.

0:07.0

My name is Johannes Ulrich.

0:09.0

And I'm recording from Jacksonville, Florida.

0:13.0

Well, the big event today, of course, Microsoft's Patch Tuesday, and with that we got patches for 99 different vulnerabilities.

0:25.4

Tenovitch are rated as critical, 87 as important and two as moderate.

0:31.9

Now the big highlight patch here is sort of for CVE 2020-064. This is the Internet Explorer Day that sort of became

0:41.9

public just a month ago, just a few days after the last patch Tuesday. This is the one where

0:49.3

Microsoft recommended you should disable jScript.dl in order to protect yourself.

0:56.0

Now, got a little bit more details now with the patch.

1:01.0

Apparently, this one affects actually Trident rendering engine in an Explorer, which also, by the way, means that Microsoft Office and so may be vulnerable to this same flaw

1:14.0

if you receive an Office document with some embedded HTML that would then also be rendered

1:21.1

using the Trident rendering engine. So this particular vulnerability has already been exploited in the wild and yes, should definitely be at the top of your patch list.

1:33.3

There are a total of four other vulnerabilities that have already been publicly disclosed.

1:39.3

Two are an elevation of perch bug in Windows installer.

1:43.3

Not really a huge deal, in my opinion.

1:46.2

Also, the security bypass in Secure Boot.

1:49.7

We had quite a few of those.

1:51.7

And there, of course, always a little bit tricky, like a secure boot is supposed to protect you if you're leaving, like, a computer unattended.

2:03.8

And then we have information disclosure bodily in Edge and IE. And Remote Desktop is that protocol is just not going away when it

2:11.7

comes to patch Tuesdays. Now this time we have two vulnerabilities that are remote code execution flaws in the

2:18.5

client component of remote desktop, so not the server.

2:23.4

Typically, to exploit these flaws, an attacker would have to convince you to connect to a malicious

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.