Windows 11: Bypass Welcome Wizard for Inplace Upgrade

Windows[German]Users who migrate from Windows 10 to Windows 11 via "Inplace Upgrade" are then greeted by a welcome wizard, which then asks for all kinds of things in various steps. Anyone who wants to upgrade several systems in view of the end of support for Windows 10 in October 2025 may be annoyed by the prompts. However, one blog reader has found a way to hide this welcome wizard.

Continue reading

Posted in Update, Windows | Tagged , | Leave a comment

Warning about Microsoft Office spoofing vulnerability CVE-2024-38200

[German]Microsoft has published a warning of an unpatched spoofing vulnerability CVE-2024-38200 on August 8, 2024 (with update on August 10, 2024). The vulnerability is included in all Office versions (Office 2016 – 2021, Office 365).

Continue reading

Posted in Office, Security | Tagged , | Leave a comment

From Sept. 1, 2024 no more license allocation in Entra ID Admin Center/Microsoft Azure Portal

[German]A small addendum for administrators who previously assigned their licenses via the Microsoft Entra ID Admin Center and/or the Microsoft Azure Portal. This will be a thing of the past from September 1, 2024 – Microsoft is consolidating license management in one place in the Microsoft 365 Admin Center.

Continue reading

Posted in Cloud | Tagged , | Leave a comment

BlackHat 2024: Remote code execution attack on M365 Copilot via email

Sicherheit (Pexels, allgemeine Nutzung)[German]Nice topic: Microsoft is pushing its Copilot via Microsoft 365 to its customers. Any user shall do something in AI – whether it's needed is secondary. Of course, this increases the attack surface and administrators have to think about security. At BlackHat 2024, Michael Bargury demonstrated RCE attacks on M365 Copilot – an email is all it takes to search for sensitivities. Here is a brief summary of this topic.

Continue reading

Posted in Security, Software | Tagged , , | Leave a comment

Microsoft Paint 3D will be retired on November 4, 2024

Windows[German]A small note to users of Windows 10 and Windows 11 who may rely on the Paint 3D program. Paint 3D, which was announced with great fanfare in 2016, will soon be buried without a sound. On November 4, 2024, Paint 3D will no longer be supported by Microsoft and will no longer receive updates. A logical step now that Microsoft no longer finds mixed reality sexy and has scrapped it.

Continue reading

Posted in Software, Windows | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Windows: NVidia graphics driver triggers BSOD on old processors

Windows[German]Small addendum to a topic that has already been known for a few days. On June 25, 2024, NVidia published the support article EOL Windows driver support for older CPUs without POPCNT instruction. There the end-of-life (EOL) for Windows driver support on older CPUs without support for the POPCNT instruction was announced.

Continue reading

Posted in issue, Windows | Tagged , , | Leave a comment

MS Edge update distribution via WSUS a bit chaotic again?

Update[German]Question for administrators who distribute their updates for the Edge browser via the WSUS: Are there any inconsistencies at the moment (August 8, 2024). A user has left a comment at this time that points to a somewhat chaotic situation with the Edge updates. Here is a brief overview of what information I have.

Continue reading

Posted in Update, Windows | Tagged , , , | Leave a comment

Windows Server at risk from PoC exploit for CVE-2024-38077

Windows[German]Another follow-up to the July 2024 patchday, in which Microsoft closed the vulnerability CVE-2024-38077 in the Windows Remote Desktop Licensing (RDL) service of Windows Server. This is a Remote Code Execution (RCE) vulnerability that has been rated with a CVSS 3.1 score of 9.8. Anyone who has not yet patched should do so immediately. A proof of concept (PoC) for this vulnerability has been published. Although this publication was taken offline again after a few hours, attacks can be expected soon.

Continue reading

Posted in Security, Update, Windows | Tagged , , , | 2 Comments

Vulnerability in Windows Update allows downgrade attacks (August 2024)

Windows[German]A security researcher from SafeBreach has taken a closer look at the Microsoft Windows update architecture. He discovered vulnerabilities in the operating system's update function (which are basically serious design flaws) that enable a downgrade attack. An attacker can thus roll back security updates that have already been installed and even prevent the installation of further updates, so that the supposedly patched vulnerabilities continue to exist. This manipulation is not recognizable and is not shown. Microsoft has been aware of this since February 2024, but has not yet provided any update to close the vulnerability – only some advisories has been published yesterday.

Continue reading

Posted in Security, Update, Windows | Tagged , , | 2 Comments

Office Updates from August 6, 2024

[German]Small addendum from Tuesday this week. On August 6, 2024 (first Tuesday of the month), Microsoft released non-security updates for Microsoft Office 2016. I'll summarize some information about these updates here in the blog.

Continue reading

Posted in Office, Update | Tagged , | Leave a comment