ISC StormCast for Wednesday, February 14th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, February 14, 2024 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.6 | It's patch Tuesday, so we got a bunch of patches to talk about today, not just Microsoft. |
| 0:21.8 | But of course, we'll start with Microsoft. |
| 0:24.0 | We got patches for a total of 80 different vulnerabilities. |
| 0:28.4 | Five of them are critical and two have already been exploited. |
| 0:33.9 | Now, the two exploited vulnerabilities are sort of similar in scope. One is an Internet Shortcut |
| 0:40.3 | File security feature bypass, and the other one, Windows Smart Screen Security feature, |
| 0:47.3 | bypass vulnerability. The problem here is that a user may download, may be offered a piece of malware, and when they're |
| 0:57.5 | trying to execute it, they're not properly being warned that this is a file they downloaded |
| 1:03.3 | from the internet. We had numerous similar vulnerabilities before. Among the critical |
| 1:10.4 | vulnerabilities, there are two that also are sort of |
| 1:13.7 | deja-vous-like vulnerabilities, one Microsoft Exchange Server, Elevation of Privilevich |
| 1:19.6 | vulnerability, and then an Outlook remote code execution vulnerability. Both are related to |
| 1:27.3 | NTLM hashes that are being leaked here. The first one, |
| 1:33.1 | the Microsoft Exchange Server vulnerability, has a CVSS score of 9.8, which of course, in particular |
| 1:41.0 | given that it's described as a privilege escalation vulnerability, |
| 1:44.9 | it's quite high, but what it really is all about is this NTLM hash relay vulnerability |
| 1:49.7 | that can be exploited to authenticate as any user where you manage to actually relay the NTLM hash. |
| 1:58.5 | Similar for the Microsoft Outlook remote code execution vulnerability, this allows Nethacker |
| 2:04.3 | even in Office protected view to then open a document in editing mode rather than protected |
| 2:12.0 | mode. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

