ISC StormCast for Wednesday, July 12th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 July 2023
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, July 12, 2023 edition of the Sans and the Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich. |
| 0:10.1 | And today I'm recording from Washington, D.C. here from Sands Fire. |
| 0:15.3 | Thanks to the listeners who attended the keynote today. |
| 0:19.5 | It was available online, not sure how many of you |
| 0:22.5 | have watched it online. A recording should also be shortly available. The link on the website |
| 0:29.2 | will eventually then link to the recording of this keynote. But well, of course, today we do |
| 0:36.7 | have Microsoft's Patch Tuesday to talk about and well, of course, today we do have Microsoft's patch Tuesday to talk about, and well, it was a quite active release of new patches. |
| 0:46.1 | 132 vulnerabilities were patched, nine of the wallablies are rated critical, and then we have six or five, depending on how you count, exploits that |
| 0:55.9 | have already been seen used in the wild, so zero days. |
| 1:01.7 | The reason I say, well, that there's five or six depending on your account, not all the |
| 1:06.6 | zero days actually have patches. |
| 1:10.1 | There is a special blog post by Microsoft about CVE |
| 1:14.5 | 2023-36884. This is a remote code execution vulnerably in Microsoft VIRT. Yes, there are details |
| 1:23.3 | about it. Yes, there are some workarounds for it, but there is no patch yet for it. An out-of-cycle |
| 1:30.3 | patch may follow shortly. Then there's also CVE 20203.3.11. This is a Microsoft Outlook |
| 1:40.0 | security feature bypass that's exploited in the wild. Exploid code can run in the preview pane, and essentially the bypass here is that security |
| 1:51.3 | warnings are not being shown. |
| 1:54.6 | And then also already exploited is a vulnerability in Windows MSHtml. |
| 2:01.6 | This could be exploited by opening a crafted file in email |
| 2:05.6 | or, of course, by visiting a malicious website. |
| 2:09.3 | MS-2020-3-32049. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

