meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 12th, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 12 May 2021

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Patch Tuesday (http.sys!!); WiFi Fragmentation/Aggregation Attacks

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, May 12, 2021 edition of the Sandtorn and Storm Center's Stormcast.

0:07.8

My name is Johannes Ulrich, and the name I'm recording from Jacksonville, Florida.

0:13.2

Well, it's patched Tuesday, of course, and if you look at sort of the high-level summary,

0:18.1

this patched Tuesday actually doesn't look too bad. It's only 55

0:21.6

vulnerabilities patched, four of them are critical and three vulnerabilities were previously

0:27.4

disclosed, but none of them has so far been exploited. But once you look closer, you may

0:34.9

have discovered the remote code execution vulnerability in the

0:38.8

HTTP protocol stack or HTTP.Sys.

0:43.5

This is labeled as CVE 2021-166 and it's exploitable without any user interaction or authentication. So a neat, warmable vulnerability.

0:58.2

So what is HTTP.Sys? Well, HTTP.Sys is essentially the implementation of the HTTP protocol

1:04.7

stack that Windows is using. IIS, for example, is built on top of it, but not really clear if IS itself is sort of

1:15.0

vulnerable here, but pretty much anything that implements HTTP on Windows, which is a lot of

1:22.5

different piece of software, are likely using HTTP.sys and may be vulnerable here.

1:30.2

What may say if you here is that only specific Windows versions are vulnerable.

1:36.4

First of all, Windows 10, which of course may be used as a web server and often is,

1:42.9

but not doing that by default.

1:45.5

And then Windows Server 20-04 and 20 H2, which of course is the sort of latest and greatest

1:54.0

version of Windows server.

1:55.8

So you may not necessarily have upgraded to these versions.

2:00.2

So one of those rare occasions where keeping, staying a little bit behind the latest and greatest

2:06.0

versions, may actually help you.

2:09.1

Microsoft does rate exploitation of this vulnerability as more likely, and well, with a CVSS

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.