ISC StormCast for Wednesday, September 11th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 September 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 11th, 2019 edition of the Sandson and Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich. |
| 0:09.7 | And then I'm recording from Sevalde, Germany. |
| 0:14.5 | Microsoft Patch Tuesday, of course, at the top of the news today. |
| 0:19.2 | And for September, we got patches for 79 different vulnerabilities. |
| 0:25.9 | Two of these patches have already been exploited and three had been previously disclosed. |
| 0:34.0 | Now as far as the exploited vulnerabilities go, one of them affects the Windows Common log file system driver. |
| 0:42.1 | We had some problems with this in the past. |
| 0:45.4 | The second one, well, good old Winsock, is actually affected by this. |
| 0:50.5 | Both are approach escalation vulnerability, so a local attacker after getting some access to the system |
| 0:57.0 | could run processes using elevated privileges. |
| 1:01.0 | 19 of the vulnerabilities are rated as critical. Now, four of them are in the remote desktop client. |
| 1:09.0 | These are remote code execution vulnerabilities, but don't mix them up |
| 1:13.4 | with these blue keep vulnerabilities. This is in the client, so it does require that a victim |
| 1:19.7 | would connect to a malicious remote desktop server. And while five of the cradle vulnerabilities |
| 1:26.8 | are still in the chakra scripting engine, this I think is sort of low compared to other months. |
| 1:35.3 | Renato Marino, who did assemble this month's summary for us, picked one vulnerability that I also think is somewhat interesting and that's a remote code |
| 1:46.4 | execution vulnerability in how link files are being processed CV 2019 1280 now link files have been |
| 1:56.8 | abused in the past heavily there have been been other vulnerabilities. So certainly this is |
| 2:02.4 | something I think that's worthwhile watching. And then unlike last month, one of the critical |
| 2:10.0 | vulnerabilities also goes to the Adobe Flash update, actually two individual |
| 2:16.8 | vulnerabilities affected by this. Both are arbitrary code |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

