ESET finds 3 critical vulnerabilities in UEFI of Lenovo consumer notebooks

[German]Users of Lenovo notebooks should react. Security vendor ESET has just announced that it has discovered three vulnerabilities (CVE-2021-3970, CVE-2021-3971, CVE-2021-3972) in the UEFI of Lenovo consumer notebooks that are rated as highly problematic from a security perspective. The exploit allows attackers to deploy and successfully execute UEFI malware such as LoJax or ESPecter on the affected devices.

Continue reading

Posted in Security | Tagged , , | Leave a comment

Free Decryptor for Yanlouwang Ransomware

Sicherheit (Pexels, allgemeine Nutzung)[German]Security vendor Kaspersky has discovered a vulnerability in the encryption of the Yanlouwang ransomware. As a result of this vulnerability, the encryption of files can be cracked under certain circumstances. Anyway, a free decryptor for Yanlouwang ransomware is available. However, samples of encrypted files and their unencrypted originals are needed for decryption.

Continue reading

Posted in Security | Tagged | Leave a comment

7-Zip vulnerability CVE-2022-29072 *doesn't* allows system privileges

Sicherheit (Pexels, allgemeine Nutzung)[German]A vulnerability CVE-2022-29072 (heap overflow) exists in the 7-Zip application up to version 21.07, which allows privilege escalation on Windows. This could allow an attacker to gain system privileges and then compromise the system at will. Here is some information about it. Addendum: Seems it was a hoax or a mistake. An extension of privileges, as originally stated by the finder, is (probably) not possible.

Continue reading

Posted in Security, Software | Tagged , | 1 Comment

Microsoft Security Update Revisions (April 15, 2022)

Short addendum from last week. Microsoft has released some Microsoft Security Update Revisions for April 15, 2022, which are changes to the documentation of various security updates in GRUB as well as in Power BI Report Server. Here is an uncommented overview.

Continue reading

Posted in Security, Update | Tagged , | Leave a comment

Windows 10 Version 21H2 in broad deployment (April 15, 2022)

Windows[German]Microsoft has again expanded the range of machines to which the Windows 10 November 2021 Update (21H2) will be offered after its release in November 2021 (see Windows 10 November 2021 Update (21H2) released). Windows 10 20H2 was already updated to version 21H2 in January 2022 (see Windows 10 20H2 will be upgraded to Windows 21H2 (January 20, 2022)). This is because older Windows 10 versions will drop out of support in May 2022 (Windows 10: Version 1909 and 20H2 reaching end of support on May 10, 2022).

Continue reading

Posted in Windows | Tagged | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


CISA Warning: New APT Cyber Tools Targets ICS/SCADA Systems

Sicherheit (Pexels, allgemeine Nutzung)[German]There is a warning from CISA and other organizations in the U.S. aimed at manufacturers and operators of process control systems and controllers (ICS/SCADA systems). Cyber groups (APTs) have developed new attack tools with which they can attack various industrial control systems. Since there is now a certain trend to only destroy in these attacks, the risk of industrial sectors or critical infrastructure being crippled by (government) cyber actors is increasing.

Continue reading

Posted in devices, Security | Tagged | Leave a comment

Microsoft Edge 100.0.1185.44 Emergency Patch

Edge[German]Microsoft has updated the Chromium Edge browser to version Edge 100.0.1185.44 as of April 15, 2022. This is an emergency update that closes the CVE-2022-1364 vulnerability (see also this page and the blog post Chrome 100.0.4896.127 fixes 0-day vulnerability CVE-2022-1364). The browser should update automatically, but can also be downloaded here. Thanks to the blog readers (German, English) for the hints.

Posted in browser, Security, Software, Update | Tagged , | Leave a comment

Comments on NGINX vulnerabilities in LDAP reference implementation (April 2022).

Sicherheit (Pexels, allgemeine Nutzung)[German]On April 9, 2022, 0-day exploit exploiting vulnerabilities in LPAP NGINX implementation became known. Spontaneously the question came up if you have to react now if you use NGINX in your environment. A blog reader sent me a note the other day about what to watch out for in this regard. Here is a quick overview of this issue.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Spring4Shell Vulnerability: Analysis and Mirai Botnet uses Spring4Shell

Sicherheit (Pexels, allgemeine Nutzung)[German]A vulnerability called Spring4Shell in the Java Spring Framework has been known for a few days. VMware has been providing patches for its products since the beginning of April 2022. It is now known that the Mirai botnet exploits the Spring4Shell vulnerability to infect systems. In addition, I came across a brief analysis from Trend Micro on the Spring4Shell vulnerability.

Continue reading

Posted in Security | Tagged | Leave a comment

Chrome 100.0.4896.127 fixes 0-day vulnerability CVE-2022-1364

[German]Google has released updates to Google Chrome 100.0.4896.127 for Android, as well as for Windows and Mac on the desktop in the stable channel as of April 14, 2022. The update closes the 0-day vulnerability CVE-2022-1364, for which an expliit already exists.

Continue reading

Posted in Android, browser, Security, Update, Windows | Tagged , , , | 2 Comments