ISC StormCast for Wednesday, May 16th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 16 May 2018
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 16th, 2018 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.9 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:12.6 | Remember how yesterday I talked about how Adobe released a PDF reader and Acrobat update, kind of surprisingly on Friday, just a couple days after |
| 0:23.2 | the usual patch Tuesday. |
| 0:25.6 | Well, it turns out that there is now working exploit code public that does affect vulnerabilities |
| 0:33.4 | being patched by this update, as well as vulnerabilities patched by Microsoft on |
| 0:39.5 | patch Tuesday. The two vulnerabilities are first of all CVE 2018 4990. This is a |
| 0:48.3 | code execution vulnerability in acrobat reader and secondly CVE 2018, 8120. |
| 0:56.6 | What apparently happened was that antivirus company ESET noticed that two PDFs were uploaded |
| 1:04.1 | to virus total that actually triggered these vulnerabilities. |
| 1:08.9 | Not clear if the actual discoverer of the vulnerabilities did |
| 1:12.6 | upload the files or if a victim inadvertently uploaded the files to a virus total. Given that |
| 1:20.3 | information about this vulnerability is now public and it wouldn't be all that hard for anybody |
| 1:26.4 | now to create a PDF exploiting the code |
| 1:29.8 | execution as well as the Burlidge escalation exploit. You should really be very careful about |
| 1:36.7 | PDFs in the near future and make sure that you expedite applying the patch from last Friday. |
| 1:43.3 | And I just checked one of the samples on Virus Total and according to Virus Total, I just |
| 1:49.7 | triggered a re-scan. |
| 1:51.5 | Only four out of 58 antivirus engines are detecting these known samples. |
| 1:57.8 | And then we got an interesting vulnerability that was disclosed in the Keeper |
| 2:03.9 | password manager API. Keeper is one of these password managers that you can use to save your |
| 2:11.9 | passwords in a wallet. And like many of these tools, it does provide the ability to sync passwords across different |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

