4.9 • 696 Ratings
🗓️ 14 July 2021
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, July 14, 2021 edition of the Sandstone at Storm Center's Stormcast. |
0:08.2 | My name is Johannes Ulrich. |
0:09.8 | And today I'm recording from Jacksonville, Florida. |
0:14.0 | Well, it's Microsoft Patch Tuesday, and it was, well, probably a little bit more than an sort of patch Tuesday with 117 vulnerabilities. |
0:23.7 | Nine vulnerabilities were either already exploited or at least publicly disclosed. |
0:28.9 | And of course, one of these nine is the famous print nightmare, print spooler vulnerability |
0:35.5 | that was patched late last week. |
0:38.8 | Now, for everybody who expected maybe another iteration of the print spooler patch, |
0:43.0 | there was no such thing, and there is not likely going to be another patch. |
0:48.0 | Microsoft has explained that the patch that they released is complete, and of course, |
0:54.0 | you also need to heed Microsoft's |
0:57.0 | configuration advice in order to completely mitigate the vulnerability, the remote code execution, |
1:03.0 | as well as the privilege escalation part of the vulnerability. There was also an interesting |
1:09.5 | vulnerability that was patched in Windows Hello. |
1:12.6 | Windows Hello is Microsoft's biometrics way to log into Windows workstations, |
1:19.6 | and apparently it was possible to essentially capture an infrared image of an individual, |
1:26.6 | then create a USB device that would emulate a camera and |
1:31.8 | just deliver this one individual frame. Of course, part of the problem here with Windows |
1:37.3 | Hello is that it has to work with a wide range of different hardware devices, unlike, for |
1:42.6 | example, Apple's Face ID, which will only work with |
1:46.2 | very specific cameras that are integrated into Apple devices. |
1:51.4 | You also got critical patches for Exchange Server again, so that's always, of course, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.