meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, November 29th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 November 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Sharepoint Attack; MSFT removes Defender App Guard for Office; Synology , Tomcat and Chrome Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, November 29, 2023 edition of the Sandsenet Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.6

Today I wrote up a quick diary about an exploit that be sort of sea gaining steam for Microsoft SharePoint vulnerability.

0:25.2

CVE 2020, 29357.

0:29.2

This is a vulnerability that Microsoft originally patched in June.

0:33.9

An exploit for it was released late September.

0:37.5

And we have seen a little trickle like one or two here and there of exploit attempts for this particular vulnerability.

0:45.6

But yesterday it really sort of started picking up and these attacks came from one particular IP address, 212, 113, 106, 100.

0:58.6

The vulnerability itself is really sort of exploited in concert with the second vulnerability, CVE 202023-24955.

1:09.0

Now, we didn't see an exploit for the second vulnerability that would be sort of a follow-up

1:15.1

if the first exploit succeeds in our honeypots. We're not emulating SharePoint close enough

1:21.2

to actually make the second vulnerability then show up. The problem here is that the first vulnerability is labeled

1:30.3

a privilege escalation vulnerability, but it's really more an authentication

1:35.3

bypass vulnerability.

1:37.3

It acts as a particular API that lists all site users.

1:43.3

That's the name sort of of the API, which includes administrators.

1:47.5

And then an attacker can use that information to actually impersonate one of those users.

1:53.6

The second vulnerability is then your remote code execution vulnerability that uses the

1:59.3

credentials or the privileges being acquired using the first

2:03.6

vulnerability. Now, when it comes to the IP address, the attacks came from, that's also kind of

2:09.3

interesting in that that particular web server that was running at that IP address was compromised

2:17.1

and had a defacement page from

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.