meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, November 15th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 November 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT and Adobe Updates; AV Quarantine Priv. Escalation;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, November 15th, 2017 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:12.7

Today we'll start with Microsoft's Patch Tuesday. We had a total of 54 different vulnerabilities being addressed. But overall it is actually a smaller and not all that

0:24.5

important patched Tuesday to what we had happened in the past. First of all, the majority of

0:31.6

vulnerabilities are really spread across three different products. In an explorer, Edge,

0:39.4

and then we have Chakra. Now, Chakra is the JavaScript and J-Script engine, so really, in some ways, part of Inan Explorer and Edge.

0:47.5

None of the vulnerabilities being patched today have been exploited in the wild, so this

0:53.8

makes us a little bit less critical, even though,

0:56.9

of course, the Etch and Explorer patches are rated critical. Another product that has, in my opinion,

1:05.3

critical patches, but Microsoft considers them only important is Office.

1:11.2

We have a total of six vulnerabilities being addressed there.

1:15.6

Probably one of the more embarrassing ones here,

1:18.1

and one I think that should probably be rated as critical,

1:21.7

is an arbitrary code execution vulnerability in the Office,

1:26.7

in particular, VERT equation editor. Turns out the equation

1:30.4

editor actually hasn't changed since 2000, same code for the last 16 years. So it doesn't have a lot

1:37.7

of the advanced protections that we have in more modern code. So it shouldn't be too hard for someone

1:43.8

to come up with an exploit for this vulnerability.

1:47.1

And also this vulnerability does not really require any user interaction other than opening

1:52.7

the Word document.

1:55.1

We also have patches for Microsoft Windows.

1:57.9

Now, here I agree with Microsoft.

2:00.0

These are important denial of service vulnerabilities,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.