4.9 • 696 Ratings
🗓️ 11 October 2016
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, October 12th, 2016 edition of the Sansonet Storm Center's Stormcast. |
0:07.0 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:12.0 | Today of course we got Microsoft's patch Tuesday to talk about and I just want to highlight a couple of patches that were released. not a lot of surprises there we do have our |
0:25.7 | typical explorer and edge roll-up patches we do have patches for office of course as we have |
0:33.0 | every month and then the other patch are all the sort of well-known components if you have patched |
0:39.9 | before. I just want to highlight a couple of the vulnerabilities that have already been exploited |
0:47.3 | in the wild and we have a total of four different vulnerabilities that have been exploited. |
0:53.6 | Now, I didn't mark all of them as patch now. |
0:58.0 | What I did instead is, for example, in an explorer, the roller patch, it does fix a vulnerability |
1:05.0 | that is already exploited in the wild, but the only thing you can do with this exploit is |
1:12.6 | check if a file exists on a system so I don't consider that severe enough |
1:19.8 | where I would call this patch now on the other hand for edge the vulnerability |
1:24.6 | that is being exploited here does allow remote code execution and this is |
1:29.9 | why for clients I did label it as patch now similar for the vulnerability in the |
1:37.0 | Microsoft graphics component it also can be used for remote code execution so I did |
1:44.0 | label it patch and now other than |
1:46.7 | that like I said no big surprises we also do again have a patch for flash |
1:53.5 | player that is being rolled out by Microsoft here now we this is not the only |
1:59.8 | bulletin or patch that Adobe came up with today. |
2:03.8 | Adobe patched Flash Player, but it also patched the PDF reader, and there's a long list |
2:11.1 | of vulnerabilities being addressed in that update. As far as patch priorities go, I would |
2:16.8 | definitely start out with the |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.