meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 15th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 15 May 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More #Intel CPU Issues; #MSFT Patches (watch out #RDP!); #Apple/#Adobe Updates; Broken Trust Seal Logs Keystrokes

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, May 15th, 2019 edition of the Santernat Storm Center's

0:07.4

Stormcast. My name is Johannes Ulrich, and today I'm recording from San Diego, California.

0:15.0

Today, Microsoft released its monthly set of patches among the 79 vulnerabilities patch.

0:22.6

Well, 23 are rated as critical and two have been known before the patch was released.

0:31.6

Now, one of these two vulnerabilities has been used in exploits already.

0:36.6

But the vulnerability that's getting probably the most attention is C2. been used in exploits already.

0:37.6

But the vulnerability that's getting probably the most attention is CVE 2019 0708.

0:46.8

This vulnerability is a problem in the remote desktop services.

0:53.0

Now it doesn't affect Windows 10. It only affects some of the older

0:56.7

operating systems like Windows 7 and earlier, Windows Server 2008, as well as 2008 R2. It goes even as

1:06.2

far back as Windows XP and Windows 2003.

1:11.6

Now usually Microsoft, of course, no longer really makes any statements regarding these older operating systems like Windows XP, but due to the severity of this particular issue, Microsoft has actually released a special patch for these

1:31.0

legacy operating systems. You can get this patch for free from Microsoft, so it's not something

1:38.3

that you have to pay some special extended service fee for. An exploit for this vulnerability should not require any user interaction, so this makes this

1:50.0

a warmable vulnerability if the RDP service is enabled.

1:56.5

Maybe worthwhile to scan your network for any systems that have the RDP service enabled that

2:02.9

shouldn't have it enabled. Usually not a great idea to leave the service exposed anyway,

2:09.7

even without this vulnerability. Another interesting vulnerability is CVE 2019-0725.

2:18.3

Well, yet another DHCP client vulnerability.

2:22.3

Haven't really seen any details here yet.

2:24.3

It's sort of interesting that this is the fourth

2:27.3

DHCP client-related vulnerability that Microsoft is patching just this year. Have been looking at this since there have been so many of these vulnerabilities, all for a sudden.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.