meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, February 13th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 February 2019

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Updates; Adobe Updates; Ubuntu snapd dirty_sock

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, February 13th, 2019 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.5

I'm recording from Jacksonville, Florida.

0:14.2

Today's big news, Microsoft's patch Tuesday, we got patches for a total of 74 different vulnerabilities, with 21 of the

0:25.7

vulnerabilities being labeled as critical.

0:29.5

Now as common in recent patch Tuesdays, there is a strong concentration of these critical

0:37.0

vulnerabilities in the scripting engine.

0:39.3

So again, these are remote code execution vulnerabilities for the most part that could be

0:44.8

executed via the web browser.

0:48.0

By the addition, we got a couple other interesting and noteworthy bulletins and patches.

0:53.9

First of all, the Microsoft Exchange privilege escalation issue that has been sort of now wrapped

1:00.5

into Patch Tuesday, but no real new information here.

1:05.8

Then we also have vulnerability against the DHCP server. Now last month we had a critical vulnerability against the DHCP server. Now, last month, we had a critical vulnerability

1:13.9

against the DHCP client. This time it's the server, which of course, well, it's a little bit more

1:19.5

tricky because if someone exploits your DHCP server, they have quite a bit of access to

1:25.9

the remainder of your network.

1:28.9

On the other hand, the HCP servers aren't really ever exposed to the outside because

1:34.1

that typically would tend to break things.

1:37.5

Microsoft, on the other hand, considers exploitation and the availability of an exploit for this

1:42.7

issue to be less likely.

1:45.0

Now there also is remote code execution vulnerability in SharePoint.

1:49.0

And SharePoint is often exposed externally.

1:53.0

However, to exploit this vulnerability, someone has to upload a SharePoint application package.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.