ISC StormCast for Wednesday, March 25th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 March 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 25th, 2020 edition of the Sansonet Storms and Stormcast. My name is |
| 0:08.0 | Johannes Ulrich. And I'm recording from Jacksonville, Florida. Microsoft released yet another update |
| 0:16.6 | to their advisory regarding the type 1 font parsing remote code execution vulnerability. |
| 0:24.4 | The one thing they sort of clarified is a little bit the targeted attacks they have seen. |
| 0:29.0 | They only targeted Windows 7 and Microsoft states that the attack against Windows 10 is unlikely due to mitigations that were put in place in the first version released in 2015, according to Microsoft. |
| 0:48.6 | They're further stating that the possibility of remote code execution is negligible for Windows 10 and elevation of privilege is not possible. |
| 1:00.4 | And talking about vulnerabilities for which there is no patch two days ago, a user reported |
| 1:08.6 | denial of service vulnerability publicly to the MAMCashD team. |
| 1:14.3 | Now, MMMCashD is a very popular, fast, noSQL database, and MMMCash 160 and MMMCash 1601 are vulnerable. |
| 1:26.8 | Now, the MMCashD team did respond rather quickly and released a fix version 162. |
| 1:34.3 | So if you're running M-Kash-D, do apply the fix. |
| 1:38.3 | It's only a denial-of-service vulnerability and you definitely should not expose M-KashECD to the open internet, which sadly |
| 1:47.9 | keeps happening. And Adobe released an update for its Creative Cloud desktop application. This |
| 1:55.4 | vulnerability being addressed with the update does allow for arbitrary file deletion. |
| 2:00.9 | Now, a couple news websites did label this as a sort of emergency patch because it was not |
| 2:07.5 | released on Adobe's patch Tuesday. |
| 2:09.9 | I believe that Adobe in recent months has more and more moved away from publishing all |
| 2:15.9 | of its patches on patch Tuesday. |
| 2:18.3 | So they have adopted a more spread out model here. |
| 2:23.3 | And really only the flash updates, if there are any, |
| 2:26.3 | they have to be sort of released on patch Tuesday if possible, |
| 2:31.3 | because they also affect Microsoft software that's then typically patched |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

