meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, March 10th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 10 March 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Patch Tuesday; Adobe Updates; Verkada Breach; git vuln

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, March 10th, 2021 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:14.3

Well, today, of course, Microsoft Patch Tuesday with 122-1 abilities being addressed, 14 of which are critical and 5 have already been exploited.

0:26.7

Two of the vulnerabilities had been disclosed prior to dispatch Tuesday being released.

0:34.1

Now out of the 5 being exploited vulnerabilities, four are of course Microsoft

0:41.2

Exchange Server vulnerabilities. These vulnerabilities were patched on March 2nd and, well,

0:48.6

we talked about them already a number of times here in the podcast, had some diaries about it. If you haven't patched

0:57.1

them yet, you're pretty certainly exploited if your exchange server is exposed to the internet.

1:03.7

The fifth vulnerability that's already being exploited is a remote code execution vulnerability

1:09.4

in Microsoft Edge and Internet Explorer 11.

1:14.2

This vulnerability can be exploited as the user visits malicious website.

1:20.9

So yeah, classic drive-by style vulnerability.

1:25.5

Now, aside of these already being used vulnerabilities, there's one that I think

1:31.3

is in particular interesting because we already had so many vulnerabilities over the last

1:36.6

12 or so month in Windows DNS server. Yes, yet another critical remote code execution

1:43.8

vulnerability in Windows DNS server with a CFSS score of 9.8.

1:50.9

This vulnerability affects the standalone DNS server as well as the DNS server integrated with Active Directory.

2:00.2

Now, in order to be vulnerable, the DNS server has to support dynamic updates.

2:06.6

Dynamic updates are typically only used sort of internally for DHCP servers and such

2:11.8

to notify the DNS server of a new host on the network and update IP address accordingly.

2:20.1

What's not really clear from the advisory is if these dynamic updates have to be

2:25.7

properly authenticated.

2:28.0

Just guessing, I think they will have to be authenticated.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.