ISC StormCast for Wednesday, September 9th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 9 September 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, September 9th, 2020 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
| 0:13.8 | Today, of course, Microsoft patched Tuesday, who thought that after a long weekend, we get a little bit of lighter patch Tuesday. |
| 0:22.5 | Nope, certainly not the case. |
| 0:24.2 | Now, 129 vulnerabilities with 23 critical. |
| 0:28.5 | I think that's about sort of average, maybe a little bit at the low end even. |
| 0:33.5 | But what's really interesting here are three vulnerabilities that are remote code execution |
| 0:40.2 | vulnerabilities in services. |
| 0:43.2 | The first one is a remote code execution vulnerability in Microsoft's SharePoint, CVE 2020, |
| 0:50.2 | 1210, with a CVSS score of 9.9. That's also the highest CSS score this month. |
| 0:59.6 | The problem here is that if an attacker is able to upload a crafted SharePoint application package, |
| 1:06.7 | well, the attacker will be able to use this to execute arbitrary code in the context of |
| 1:15.3 | the SharePoint server. |
| 1:17.8 | So here the real hurdle is kind of to be able to upload this application package, but I'm |
| 1:23.9 | sure attackers will find creative ways to make this happen. |
| 1:29.8 | Second one, Microsoft Exchange, CVE 2020, 16875. |
| 1:37.0 | The CVSS score 9.1, so still in the 9 and with that critical range. |
| 1:50.0 | In order to exploit this vulnerability, all the ad hacker has to do is send a crafted email to a vulnerable exchange server, well, and that's what exchange servers are good for. |
| 1:56.0 | So I would think this is definitely something that's possible to exploit. |
| 2:02.6 | Code being executed would run as the system user, |
| 2:05.7 | which I think is what the Exchange Server runs as. |
| 2:08.8 | So that's probably why it is the system user, |
| 2:12.0 | but please correct me if I'm wrong here. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

