Windows 10 Update KB5017308 causes issues when creating/copying files via GPO

Windows[German]Sort September 2022 patchday recap. It looks like the cumulative (security) update KB5017308 released on September 13, 2022 for Windows 10 comes with collateral damage. I have received several reports from readers that following the update installation, creating or copying files via GPO or creating GPO settings files no longer works.

Continue reading

Posted in issue, Security, Update, Windows | Tagged , , , , | 18 Comments

Lenovo BIOS/UEFI updates fix vulnerabilities, hundreds of models affected (9.2022)

[German]Chinese computer manufacturer Lenovo has released updates for the BIOS/UEFI of hundreds of its computer models. These are intended to address serious vulnerabilities (CVE-2021-28216, CVE-2022-40134, CVE-2022-40135, CVE-2022-40136, CVE-2022-40137), which Lenovo describes in a security advisory. 

Continue reading

Posted in devices, Security, Update | Tagged , , , | Leave a comment

.NET Framework-Updates September 2022

UpdateAs of September 13, 2022, Microsoft has released a few more updates for the .NET Framework. Bolko pointed it out here (thanks for that). Update KB5017529 is the Security and Quality Rollup for .NET Framework 3.5.1, 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8 for Windows 7 SP1 and Windows Server 2008 R2 SP1 and includes KB5017036 (.NET 4.8) and KB5016368 (.NET 4.7). Furthermore there is the Microsoft .NET Desktop Runtime 6.0.9. The colleagues from deskmodder.de reported that .NET 6.0.9 and .NET Core 3.1.29 close the (severe) denial of service vulnerability CVE-2022-38013.

Posted in Security, Software, Update | Tagged , | Leave a comment

0patch fixes Memory Corruption vulnerability (CVE-2022-35742) in Microsoft Outlook 2010

[German]The vulnerability CVE-2022-35742 in Outlook was closed by Microsoft in August 2022 by means of security updates (see Patchday: Microsoft Office Updates (August 9, 2022)). However, Microsoft only provides updates for the MSI versions of Outlook 2013 and 2016. ACROS Security has now released a micropatch that closes the vulnerability in Microsoft Outlook 2010.

Continue reading

Posted in Office, Security | Tagged , | Leave a comment

Court documents show how Google monitors users despite rejected tracking

Sicherheit (Pexels, allgemeine Nutzung)[German]A recent lawsuit filed by the Arizona Attorney General against technology company Google shows that the company continues to track users who have declined location tracking anyway. Thus, IP addresses of Google users served to obtain accurate location information and then used for Google services. On October 24, 2022, Arizona's lawsuit against Google is scheduled to be heard – and I think the EU will be watching closely as well, since Google is in the sights of EU antitrust watchdogs for various competition complaints and there are also GDPR complaints from consumer protection organizations.

Continue reading

Posted in Security | Tagged , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Patchday: Microsoft Office Updates (September 13, 2022)

Update[German]On September 13, 2022 (second Tuesday of the month, Microsoft Patchday), Microsoft released several security-related updates for still-supported Microsoft Office versions and other products. The updates are available for the installable MSI version of Microsoft Office (the click-to-run packages obtain the updates through other channels). Office 2019 does not appear in the list because it is distributed via click-to-run packages and receives security updates via the Office Update feature. Below is an overview of the available updates.

Continue reading

Posted in Office, Security, Update | Tagged , , , | Leave a comment

VMware ESXi: Retbleed fixes cause 70% performance loss in Linux VMs running kernel 5.19

In performance regression testing, VMware testers found a severe performance drop for Linux guests when running kernel 5.19 in a VMware ESXi virtual machine with the Retbleed fixes installed. The degradation was up to 70% for computing, up to 30% in networking, and up to 13% in memory usage. Details can be found in this post. (via)

Posted in Linux | Tagged , | Leave a comment

Trend Micro Apex One: Patch Critical Vulnerabilities (Sept. 2022)

Sicherheit (Pexels, allgemeine Nutzung)[German]Trend Micro warns of various vulnerabilities, including a remote execution vulnerability (RCE), in its security solution Trend Micro Apex One. This vulnerability in the endpoint security solution is said to be already exploited. However, Trend Micro has released an update to its software that addresses the vulnerability. Administrators using Trend Micro Apex One should update this software in a timely manner.

Continue reading

Posted in Security, Software, Update, Windows | Tagged , , , | Leave a comment

EU court confirms billion-dollar fine against Google over Android restrictions

[German]The Court of Justice of the European Union issued a decision on Wednesday, September 14, 2022, regarding the fine imposed by the EU Commission on Google or its parent Alphabet. In Case T-604/18, the court largely upheld the Commission's decision that Google imposed unlawful restrictions on Android mobile device manufacturers and mobile network operators in order to strengthen the dominant position of its search engine.

Continue reading

Posted in Android, General | Tagged , , , | Leave a comment

Mitel MiVoice Connect is attacked by Lorenz ransomware

Sicherheit (Pexels, allgemeine Nutzung)[German]Phone systems from Canadian manufacturer Mitel that are used in companies are being attacked by ransomware from the Lorenz Group. Arctic Wolf Labs suspects that Lorenz Ransomware Group has exploited the CVE-2022-29499 vulnerability to compromise Mitel MiVoice Connect systems to gain initial access. After that, the system can be taken over to encrypt it and extort victims. Administrators should update the phone system software to the latest version.

Continue reading

Posted in devices, Security | Tagged , | Leave a comment