ISC StormCast for Wednesday, January 13th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 January 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, January 13th, 2021 edition of the Sands and at Storm Center's Stormcast. |
| 0:08.6 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:14.5 | Of course, top of the news today is, as usual on Patch Tuesday, the Microsoft Patch Tuesday Crop and the Got Patches for 83 vulnerabilities, |
| 0:25.6 | 10 of which are rated as critical. |
| 0:29.6 | The one that sort of caught the most attention is CVE 2021-1647. |
| 0:37.1 | This is a remote code execution vulnerability in Microsoft Defender, so essentially in Microsoft's |
| 0:45.2 | security tools. |
| 0:46.8 | CVSS rating for this is 7.8. |
| 0:50.2 | Now, what makes it even more exciting is that this vulnerability is apparently already being exploited in the while. |
| 1:00.3 | A little bit unusual is also that we do have nine vulnerabilities that were patched in the remote procedure call runtime, and well, these vulnerabilities can lead to remote code execution. |
| 1:12.7 | Five of these vulnerabilities are rated as critical, with a base CVSS score of 8.8. |
| 1:21.4 | These vulnerabilities are exposed over the network, but an attacker would need some |
| 1:27.1 | credential, some access to the target system in order |
| 1:31.0 | to exploit these vulnerabilities. But then we also had a flaw that didn't get patched this |
| 1:38.1 | month that sort of was expected to be addressed this month, and that's a remote code execution vulnerability in exchange server. |
| 1:46.7 | Initially, this flaw, I believe, was patched in September or so last year. |
| 1:51.7 | The researcher that found the original vulnerability then did post about two possible bypasses for this patch. |
| 2:01.6 | One was addressed in December. |
| 2:04.6 | One is now still outstanding. |
| 2:07.6 | But this remote code execution also does require some credentials, |
| 2:12.6 | which makes exploitation, of course, less likely. |
| 2:16.6 | Now, not included in the patch count this month are patches for Microsoft Edge as it's now part |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

