4.9 • 696 Ratings
🗓️ 13 May 2020
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, May 13th, 2020 edition of the Sansanet Storm Center's |
0:07.8 | Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
0:14.1 | Of course, we got Microsoft's patched Tuesday to start out with, now many have sort of expected |
0:20.2 | a lighter patch Tuesday. |
0:22.9 | I would rate it as average. |
0:24.9 | We have a total of 111 vulnerabilities being addressed, and 16 of these vulnerabilities are rated |
0:32.2 | critical. |
0:33.7 | On the good side, none of the vulnerabilities have been disclosed previously and none of them |
0:40.2 | have already been exploited. |
0:43.6 | Now the one vulnerability that sort of caught a little bit my attention was a vulnerability |
0:50.4 | or actually three vulnerabilities in Microsoft SharePoint and these are remote code |
0:56.4 | execution vulnerabilities. All three are rated critical. However, in order to exploit this |
1:03.5 | vulnerability, an attacker would have to be able to upload a crafted SharePoint application package to an affected version of SharePoint. |
1:16.5 | So certainly one of those things that you probably do want to address quickly because SharePoint |
1:20.8 | tends to be a little bit more exposed. The other critical vulnerabilities are for the most part |
1:27.2 | confined to the web browser |
1:30.0 | and related software, at least as far as exploitability goes. |
1:34.6 | So well, certainly nothing that you should ignore, but on the other hand, it's also more |
1:38.9 | of the same that we get every single month. |
1:44.6 | From Adobe, we only got patches for the Adobe DNG software development kit, which are probably |
1:52.2 | not really all that big of a problem, but then we also got patches for a pretty long list, |
2:00.0 | I think 24 different vulnerabilities in Adobe Acrobat |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.