ISC StormCast for Wednesday, September 13th 2017
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 13 September 2017
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 13th, 2017 edition of the Sandinert Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Las Vegas, Nevada. |
| 0:13.3 | Today, of course, Microsoft's patch Tuesday, sort of an average patch Tuesday, we have a total of four vulnerabilities that are being addressed |
| 0:23.2 | here that were either already known or have already been exploited in the wild. |
| 0:30.1 | Probably the most significant vulnerability here is CVE 2017-8759. This is the the vulnerability already has been exploited in the wild. |
| 0:41.9 | Fire Eye has a good write-up about it. They assign it to Finfisher. Now the vulnerability here is |
| 0:50.0 | actually in a dot-net component that parses soap. |
| 0:59.3 | But the way it's being exploited is via Microsoft Office. |
| 1:03.8 | What fire I saw here was VIRD documents being delivered that then when opened, not in protected mode, |
| 1:08.3 | are triggering this vulnerability. |
| 1:11.3 | So Office or Microsoft VIRD is really more the delivery vector. |
| 1:15.4 | The actual vulnerability is in dot net. |
| 1:18.9 | Typical for FinFisher. |
| 1:20.3 | This has been used in targeted attacks, |
| 1:22.5 | so nothing in widespread use yet. |
| 1:26.0 | Microsoft rated the exploitative ability with zero, well, meaning that it's |
| 1:30.2 | already been used in the wild. The other three already disclosed or exploited issues aren't |
| 1:36.7 | really all that critical. First one, well, another fix for the prod come, prod-pound vulnerability, |
| 1:47.4 | this time affecting Microsoft's HoloLens. |
| 1:52.5 | Don't think it's really in that widespread used to be that significant, really. |
| 1:56.8 | Then we do have another update for Device Guard. |
| 1:59.7 | This is really more security feature bypass. And finally, an update to Microsoft Edge's content security policy. |
| 2:06.6 | There was a vulnerability that allowed you to bypass content security policy in Microsoft Edge. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

