meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, June 5th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 June 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Notepad Bug; vim bug; New RDP Vulnerability; @rawsec @taviso

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, June 5th, 2019 edition of the Sands and its Storms on a storm

0:05.5

star, Stormcast. My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:13.9

Travis Ormandy of Google's Saturday project has reported vulnerability in Notepad of all applications.

0:23.6

Apparently some memory corruption error that could be used to actually execute arbitrary code.

0:30.6

Well, it's of course always curious to see a bug like this in an application like Notepad.

0:36.6

It's not yet clear how exploitable this is, no details

0:40.5

at this point. Tavis only tweeted that he reported this vulnerability to Microsoft. Of course,

0:48.3

it's always curious to have a vulnerability in software like Notepad.

0:54.4

What we have to see is how exploitable all of this will be likely it requires that the

0:59.8

victim will open a document in Notepad.

1:03.5

But remember how sometimes people like to actually use Notepad to open suspicious documents

1:10.1

because Notepad sort of has this reputation of being a simple

1:13.6

safe application to do this.

1:16.6

And not to be left alone here to match the notepad vulnerability, we also have details regarding

1:25.6

vulnerability in WIM and NeoWIM.

1:29.3

Now this vulnerability has been patched already was originally reported to the maintainers on May 22nd and

1:38.3

patched release came out on May 23rd for WIM and 29th for NeoWim. This feature is related to MOTLines.

1:48.8

Now, Mone Lines is a tricky feature in WIM. Essentially, what you can do with them is add special

1:54.6

lines to a text file that alter how WIM works. It's often used, for example, in code files in order to, for example,

2:05.4

set certain tap stops and alike, but can also, like in this case, use to execute arbitrary

2:13.0

commands. While this particular vulnerability has been patched now, the finder of the vulnerability

2:20.3

does recommend that you disable mode lines in WIM which can easily be done via the WIM configuration

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.