4.9 • 696 Ratings
🗓️ 15 March 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, March 15th, 2020, 3 edition of the Sands and its Storms anders |
0:08.1 | Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:15.8 | Well, it's patch Tuesday, so sorry, lots of patches in today's podcast, starting of course with Microsoft, |
0:24.1 | according to Renato's count, who as usual created the diary today for us. We got 76 vulnerabilities |
0:32.0 | patched, nine of them are critical and two are already being exploited. |
0:38.7 | One of the exploited vulnerabilities, it's a vulnerability in Microsoft Outlook, has actually been |
0:44.7 | exploited for about a year since April last year, in highly targeted attacks, in particular |
0:52.1 | against some Eastern European governments. Russia |
0:56.6 | supposedly was behind these attacks. And it does actually use a relatively old style vulnerability. |
1:03.3 | It's against Microsoft Outlook. And the trick here is that you can get Microsoft Outlook to connect |
1:09.4 | to an SMB share. We have had this in many other contexts |
1:13.6 | where a link pointing to an SMB share would result in the system automatically reaching out to that SMB share, |
1:22.6 | and with that of course passing credentials, which could be downgraded to NTLM hashes, which then, of course, |
1:31.0 | can easily be used in an NTLM relay attack. |
1:34.6 | So if you have outbound port 445 blocked, you're actually safe here, at least against the attack |
1:41.8 | leaking credentials to the outside. |
1:45.6 | This attack and the credentials were then often used to exfiltrate emails. But exploitation, now that the vulnerability is known, |
1:53.3 | is really relatively straightforward, just requires the right URL in the right Mappy property, |
2:00.2 | and you're pretty much all set there. CVSS for this |
2:04.5 | is 9.8. The second vulnerability is also sort of in a feature that has had issues before. Windows |
2:13.5 | Smart Screen, that's the entire mark of the web business, where if you download a file |
2:19.2 | from the internet, it has this mark of the web attached, so when you're opening it, it will |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.