ISC StormCast for Wednesday, June 12th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 June 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 12, 2019 edition of the Sansand-Stormsanders Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and today I'm recording from Neptune, New Jersey. |
| 0:12.4 | Microsoft's patch Tuesday, of course, is at the top of the news. |
| 0:16.4 | Today, 88 total vulnerabilities being patched. |
| 0:20.7 | Most of the critical vulnerabilities are located in the |
| 0:24.3 | browser or the scripting engine which of course is sort of part of the browser. Some interesting |
| 0:31.2 | critical vulnerabilities outside of these browser vulnerabilities. The Microsoft Speech API has a remote code execution |
| 0:39.0 | vulnerability. Now in order to trigger this you would have to convince a victim to |
| 0:44.3 | actually try to convert a piece of text that you send them to speech using that API. In |
| 0:52.7 | addition we also have three critical vulnerabilities in Windows HyperV. These are remote code execution vulnerabilities. |
| 1:02.0 | Now, and then we also do have four Pro-Ridge escalation vulnerabilities that are rated important that already have been disclosed. I believe these are essentially these vulnerabilities disclosed by Sandbox Escaper over the last couple of weeks. |
| 1:19.2 | And as usual, we also got updates from Adobe. |
| 1:23.1 | One remote code execution vulnerability is patched in Flash Player. Probably at least as important are three code execution vulnerabilities in Cold Fusion. |
| 1:34.3 | So don't forget to patch this. |
| 1:36.8 | We have seen this often being exploited in the past. |
| 1:40.3 | And then we also have a couple of vulnerabilities being addressed in Adobe campaign classic. |
| 1:45.0 | Well, I don't think that tool is particularly that often used. |
| 1:48.0 | It's a business marketing tool, but if you use it, well, definitely do pay attention to it. |
| 1:54.0 | So in general, from the Adobe and Microsoft side, I would call this an overall average patch Tuesday. |
| 2:02.6 | And this month, Intel and SAP also joined the patching fund. |
| 2:06.6 | Nothing really all that terribly noteworthy from Intel, a number of firmer updates and the like. |
| 2:13.6 | As far as SAP is concerned, one of the vulnerabilities that they're addressing here, and they release the total of 11 security notes, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

