meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 11th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 11 January 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Patch Tuesday; Cacti Vuln Details; Text-to-SQL Vulnerabilities

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, January 11th, 2023 edition of the Sandcent Storm Center's Stormcast.

0:09.6

My name is Johannes Ulrich.

0:11.2

And then I'm recording from Jacksonville, Florida.

0:15.5

Well, it's a patched Tuesday, and of course we got to talk about Microsoft a total of 98 vulnerabilities being

0:22.6

patched. Sometimes people ask you know why they see other numbers being quoted in other

0:27.8

articles. We typically also consider the chromium vulnerabilities that are being

0:33.0

patched as part of Microsoft Edge. We also sometimes include advisories that Microsoft Patch publishes that are not technically

0:43.3

patches, but just some sort of updated configuration guidance and such.

0:48.3

But anyway, so let's dive in what we got here.

0:52.3

Nothing really overly exciting, I think, this month. We got one

0:57.6

exploit, one vulnerability that has already been exploited, and that's an elevation of privilege

1:03.9

vulnerability in the Windows Advanced Local Procedure Call, CVE 2020- 23, 21674.

1:13.4

Interesting here is it's not just sort of a simple privilege escalation, but it's also a browser

1:18.1

sandbox escape vulnerability.

1:20.6

So this would be the vulnerability you need to turn a browser vulnerability into sort of

1:25.8

unrestricted system privileges.

1:29.0

And yeah, definitely something you should pay attention to.

1:32.4

And as I said, it's already being exploited.

1:35.8

We also have previously disclosed vulnerability that has not yet been exploited as far

1:42.3

as Microsoft knows.

1:43.8

And that's another privilege escalation vulnerability

1:46.1

in the Windows SMB witness service. That are critical vulnerabilities affect the Microsoft

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.