ISC StormCast for Wednesday, March 9th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 March 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, March 9th, 2020 edition of the Santernet Stormsterners Stormcast. My name is Johannes Ulrich. And today I am recording from London, England. |
| 0:13.5 | Well, as I'm recording this, it's patched Tuesday, and with that we got from Microsoft patches for 92 different vulnerabilities. |
| 0:22.8 | Out of these 92, 3 R-rated critical, |
| 0:26.8 | three have already been disclosed previously, |
| 0:29.3 | but none of them has already been exploited. |
| 0:33.4 | Probably the most interesting vulnerability here, |
| 0:35.2 | I think is actually the RDP client vulnerability. |
| 0:38.8 | It's a remote code execution vulnerability. |
| 0:41.5 | An attacker would have to trick the victim to connect to a malicious RDP server. |
| 0:48.5 | That's usually accomplished via a URL and has been done in the past. |
| 0:53.7 | Microsoft does rate this vulnerability as more likely to be exploited, |
| 0:59.0 | and details have already been released. |
| 1:03.0 | Another critical vulnerability that we have here is CVE 2020-23277. |
| 1:10.0 | This is a remote code execution vulnerability in Microsoft Exchange server. |
| 1:14.6 | It does require credentials, but any credentials will do and the code will be executed |
| 1:20.4 | with elevated approaches, so certainly something to take serious. Two more critical |
| 1:27.1 | vulnerabilities here are the remote code execution |
| 1:30.6 | vulnerability in the HEVC and the VP9 video extensions. So in order to exploit this, well, all we have |
| 1:37.6 | to do is get the user to click on a link in order to view a video. And this may then lead to the code execution using that particular |
| 1:49.0 | user's privileges. The number of 92 vulnerabilities also does include chromium patches so they may |
| 1:57.8 | have been released a few days earlier, |
| 2:04.4 | but they're always sort of included in the list of patches for the particular patch Tuesday. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

