ISC StormCast for Wednesday, March 15th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 March 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 15th, 2017 edition of the Sands and at Storm Center's Stormcast. My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:12.7 | Today, of course, Microsoft patched Tuesday, and it was a bit larger than normal given that Microsoft skipped the February edition. |
| 0:21.8 | In February we only got Adobe's bulletin, which was, as usual, republished by Microsoft. |
| 0:29.4 | So 18 bulletins total, a bit more than normal, not necessarily twice than normal, but given |
| 0:35.7 | that some of the bulletins probably got combined |
| 0:39.6 | between February and March, like for example the Internet Explorer and Internet Edge |
| 0:45.7 | Bulletin. |
| 0:46.9 | As mentioned in a diary I wrote up earlier today, probably the most scary bulletin here is |
| 0:53.7 | the one that affects SMB servers. |
| 0:57.0 | There are a total of five different vulnerabilities that are being addressed by this bulletin |
| 1:04.0 | that do allow remote code execution vulnerabilities for unauthenticated users. |
| 1:10.0 | So this does indeed sound quite warmable, |
| 1:14.6 | certainly very dangerous, given that SMB is still often exposed. |
| 1:20.6 | Now Microsoft also rates the exploitability of these vulnerabilities with one, |
| 1:26.6 | which is the lowest rating that Microsoft |
| 1:29.8 | offers and means that we will likely see exploits for these vulnerabilities. |
| 1:36.6 | And then we got two more server-related bulletins. The first one, MS-1715, which affects Outlook web access, and MS-17-16, which affects |
| 1:49.3 | IIS. |
| 1:50.6 | Both of them are cross-site scripting vulnerabilities. |
| 1:53.9 | So what you can do with that particular vulnerability depends very much on the user you can snare into clicking on a link or get exposed |
| 2:05.4 | to the JavaScript. |
| 2:07.7 | There are also six different bulletins that either fix a vulnerability that already has been |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

