meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, March 13th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 13 March 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Patch Tuesday; NVD Issues; ZOHO ManageEngine Vuln; Arube Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, March 13th, 2020,

0:04.6

for edition of the Santernet Storm Center's Stormcast.

0:08.4

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.6

Well, it's patch Tuesday, so yes, today's podcast will cover a lot of patches.

0:22.3

And of course, let's start with Microsoft.

0:25.0

Microsoft delivered patches for 60 different vulnerabilities.

0:30.3

In addition to that, we also got four patches from chromium that affect Microsoft Edge.

0:39.0

60 vulnerabilities is sort of a little bit on the average,

0:42.8

maybe a little bit of the lower side,

0:44.0

but what's kind of really surprising is

0:45.8

there are no vulnerabilities here that are already being exploited,

0:49.3

so no zero days, no vulnerabilities that are already disclosed,

0:53.5

and we only have a total of two

0:56.4

critical vulnerabilities. And one of them is actually a denial of service vulnerability. Both

1:03.9

of the critical vulnerabilities are affecting Hyper V. Again, one is denial of service vulnerability.

1:10.0

The other, the remote code execution vulnerability,

1:12.6

does require that NetHacker actually has access to a virtual machine running within HyperV.

1:20.6

So it's really more one of these virtual machine escape vulnerabilities.

1:25.6

Other than that, there are a couple other, actually one specific vulnerability sort of of interest,

1:31.7

and that's remote code execution vulnerability in exchange server.

1:37.1

Now, this doesn't look like it's super easy to exploit.

1:40.6

It first requires that attacker already does have access to the exchange server,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.