meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, November 11th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 11 November 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Patch Tuesday; Platypus; Adobe/Firefox Updates; Fingerprinting ADS-B

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, November 11th, 2020 edition of the Sandstone Storm Center's Stormcast. My name is Johannes Ulrich.

0:10.0

And I'm recording from Jacksonville, Florida.

0:14.8

Well, it's Microsoft's patched Tuesday, so let's start with that. We received a total of 110 or 112 patches, depending on how you exactly count them, with 17 of them being rated as critical.

0:33.3

And then there is one that was previously disclosed. That's the one that we talked about.

0:38.9

I believe it was last week, the one privilege escalation vulnerability that Google has

0:46.2

disclosed and made public.

0:47.8

And Google already had seen this being exploited in the wild.

0:59.0

Overall, this I think isn't actually the most important vulnerability here. We do have, for example, CVE 202017.5.1.

1:05.0

That's a vulnerability in the Windows network file system, and it can be exploited remotely, doesn't require any

1:15.2

authentication, and has a CVSS score of 9.8. Microsoft also rates exploitation of this

1:23.8

vulnerability as more likely. And while it wouldn't be patched Tuesday without the new Microsoft SharePoint vulnerability,

1:31.8

I think that's always something to look for.

1:35.7

So CVE 2020-17061.

1:40.5

Now this one also makes it too important with a Microsoft's scale with a CVSS score of 8.8.

1:51.0

Sort of interesting also a number of critical vulnerability in the HEIF image extension and the HEV. video extension. These formats may not be as much household

2:04.9

names as JPEC and JIF, but they are the default file formats in iOS 11 and later, and so

2:14.0

you'll definitely see them from mobile devices and Macs.

2:19.3

Windows 10 started to support these file formats with the October 2018 update.

2:28.3

And with your Windows update, you may also receive a new microcode from Intel for its CPUs fixing yet another

2:38.3

side channel attack. These side channel attacks just don't seem to be going away. And interesting

2:45.2

feature that's being abused here, the running average power limit or Rappel feature in some of these CPUs, which

2:53.6

is really intended to limit the power consumed by a particular CPU, for example, in data

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.