ISC StormCast for Wednesday, July 10th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 10 July 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, July 10th, 2019 edition of the Sansonet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich. |
| 0:09.2 | And then I'm recording from London, England. |
| 0:12.7 | Of course, today we'll have to start with Microsoft's Patch Tuesday. |
| 0:17.3 | We got patches for a total of 77 different vulnerabilities, 15 of which are rated as |
| 0:26.5 | critical. Among those vulnerabilities, there are two privilege escalation vulnerabilities that have |
| 0:32.0 | already been exploited in the wild. Now, five additional vulnerabilities have been disclosed by Google's |
| 0:41.0 | project zero ahead of this patch Tuesday. None of these vulnerabilities have been exploited, yet |
| 0:49.3 | the one that sort of sounded the most dangerous one was CBE 2019 1068. |
| 0:57.0 | This one is this Microsoft SQL Server remote code execution vulnerability, |
| 1:02.0 | but exploitation requires that an attacker is able to submit SQL queries to the Microsoft SQL server. |
| 1:12.7 | So possibly exploitable via maybe SQL injection in a vulnerable web application. |
| 1:19.2 | Interesting to note also that there is one vulnerability CVE 2019, 1130. |
| 1:26.1 | That's another evaluation of privilege vulnerability that was reported by Sandbox |
| 1:31.4 | Escaper. In the past Sandbox Escaper, tenant to release details about vulnerabilities publicly |
| 1:38.8 | via Twitter. This particular vulnerability appears to have been reported privately to Microsoft. |
| 1:47.3 | Other than the fact that the number of vulnerabilities is a bit higher than what we usually see, |
| 1:54.2 | the rest of the vulnerabilities are pretty much standard. |
| 1:57.9 | Most of the critical vulnerabilities are confined to the scripting engines and the browser. |
| 2:04.2 | So again, your web browser remains a huge target here and you definitely should try to apply these |
| 2:12.1 | patches quickly. Now, one vulnerability that's not actually related to the browser is critical remote code execution vulnerability in the DHCP server. |
| 2:23.5 | That sort of continues that trend of vulnerabilities related to DHCP. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

