meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 9th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 9 January 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Patch Tuesday; Adobe Updates; Google Play Store Adware; ETC 51% Attack

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 9th, 2019 edition of the Santernut Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida.

0:12.0

Big news today, of course, Microsoft's patched Tuesday. We got 49 or 51 vulnerability's patch,

0:20.0

depending on how you exactly count them.

0:23.1

Only eight of them, I believe, are rated critical.

0:26.4

So overall, an average patch Tuesday, one vulnerability was already publicly known, but this

0:33.1

time around, no vulnerability is fixed that has already been exploited. Now, there is one

0:39.9

vulnerability that sort of sticks out, and that's CVE 2019 547. This is a vulnerability in

0:47.5

the Windows 10 or server version 1803, the HCP client. So interestingly, only the latest, greatest operating system versions are vulnerable,

0:59.2

older versions are not affected.

1:02.1

The tricky part here is that this is one of those vulnerabilities you can't really do

1:07.0

much about.

1:08.5

You have to accept the HCP leases in many networks, in particular

1:12.8

if you of course you're connecting to a Wi-Fi network somewhere. So this would be a classic

1:18.4

vulnerability to be exploited by a rogue access point, for example. At this point, we don't

1:25.7

really know much about this vulnerability other than what Microsoft

1:28.3

told us and, well, one of the items Microsoft noted is that it shouldn't be all that difficult

1:33.6

to write an exploit for this and that exploitation is likely for this vulnerability. So this one

1:41.1

vulnerability should certainly be sort of at the top of your patch priority list.

1:46.6

Another big issue is CV 2019 586.

1:52.5

This vulnerability affects Microsoft Exchange and it does allow an attacker to take control

1:59.1

off an exchange server just by sending a specially crafted email

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.