ISC StormCast for Wednesday, October 11th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 October 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 11th, 2017 edition of the Santernut Storm Center's Stormcast. |
| 0:07.8 | My name is Johannes Ulrich, and I'm recording from Singapore. |
| 0:11.2 | Microsoft patched Tuesday, of course, brought us, again, a set of interesting patches. |
| 0:17.1 | 66 vulnerabilities totally patched in this particular update. I want to start with one particular |
| 0:23.6 | vulnerability here that I labeled as patch now and this is a vulnerability in office. CVE 2017, |
| 0:32.6 | 11826. The reason I label it as patch now is it's already being exploited in the wild. |
| 0:40.3 | It's yet another RTF vulnerability. |
| 0:44.3 | Chihu 360 who did actually detect the exploitation of this vulnerability, |
| 0:51.3 | did see an RTF document with an embedded VIRT-DUCS document that was used here |
| 1:00.0 | anywhere between August and September to compromise a system using an exploit that targets this vulnerability. |
| 1:10.0 | On a good side, Chi-Hu-360 did not make public a lot of details about the exploit, so as far |
| 1:16.1 | as I know, there is no public available exploit at this point. |
| 1:21.8 | There are two additional vulnerabilities where some details were already available. |
| 1:26.6 | Public. One wassad scripting |
| 1:29.1 | vulnerability in SharePoint and the second one denial of service vulnerability |
| 1:35.0 | in the Windows subsystem for Linux both of these have not yet been actually |
| 1:41.5 | exploited these shared point cross-sets scripting vulnerabilities, |
| 1:46.0 | they're always somewhat interesting |
| 1:47.9 | because it definitely can be used in some targeted attacks |
| 1:51.0 | in order to, for example, extract credentials and the like |
| 1:54.7 | from users of SharePoint. |
| 1:57.7 | And we got a couple of SMB vulnerabilities here, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

