meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 12th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 12 January 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Patch Tuesday (#wormable #http.sys vuln); Adobe Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 12, 2020 edition of the Sansonet Storm Center's

0:06.3

Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.1

Let's patch Tuesday, and with that we got patches for 126 different vulnerabilities. Well,

0:19.4

that includes the chromium vulnerabilities that affect Microsoft Edge,

0:24.6

which were technically released last week. But well, the headliner of this patch Tuesday

0:32.6

is CVE 2022-21907.

0:37.9

This vulnerability affects HTTP.Sys.

0:41.3

That's the basic HTTP processor on Windows, and with that, of course, IIS, and everything

0:48.5

else on Windows that pretty much deals with HTTP.

0:52.8

So a commonly exposed component last big vulnerability here,

0:56.4

I remember was the range header from a couple of years back,

0:59.8

and certainly something that's often exposed.

1:04.1

This is a big deal, it's a warmable vulnerability.

1:08.4

It does allow for code execution. It does require no user interaction,

1:14.3

and many versions of Windows are vulnerable by default, in particular more recent versions

1:21.1

like 2022, 20H2 core, and various Windows 10 and Windows 11 versions. The only recent versions of Windows that

1:30.6

are not vulnerable by default is Windows Server 2019 and Windows Server 10 version 1809. These

1:39.3

two versions are vulnerable technically, but the feature,DP trailers is not enabled by default.

1:47.4

So let me elaborate a little bit on what these HEPP trailers are all about.

1:51.5

Most of you are probably familiar with HDP headers that you have at the beginning of a request

1:56.6

or a response, and then you typically have an HDP1.1 at least, an empty line, and then you

2:02.3

follow the response or request body.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.