meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, September 14th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 14 September 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Microsoft Patch Tuesday; Adobe Patches; Magento Extension Hack;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, September 14th, 2020 edition of the Sands and its Storm centers, Stormcast.

0:10.2

My name is Johannes Ulrich, and I am recording from Jacksonville, Florida.

0:16.0

It's patched Tuesday again, and with that we got patches for 79 different vulnerabilities including

0:24.1

one vulnerability that is already being exploited wouldn't be patched Tuesday without at least

0:31.5

one little seraday like that so let's start with the one that's already being exploited. CVE 2022-37-9. It's a

0:42.2

privilege escalation vulnerability in the Windows common log system driver and details have

0:48.9

already been made public according to Microsoft. So it's not only being exploited, it's already publicly known.

0:57.3

In April, Microsoft actually patched a similar vulnerability in the common log file system

1:03.7

driver.

1:04.5

So there is a chance that this was more or less just an additional fix for this vulnerability,

1:10.7

that there was a way to bypass the original patch.

1:15.0

We have seen this before, but not enough detail at this point to really confirm this.

1:20.3

These days, I do not really get terribly excited about privilege escalation serendos like this.

1:26.2

After all, they appear to be coming

1:27.7

sort of out on almost

1:29.1

weekly schedule.

1:31.0

More interesting in some ways

1:32.7

are a couple of other

1:34.8

vulnerabilities.

1:36.3

CVE 2020-32-34-7-18.

1:39.6

It's a remote code

1:41.2

execution vulnerability in the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.