Exchange Server: Authentication bypass with ProxyToken

Sicherheit (Pexels, allgemeine Nutzung)[German]In the April 2021 cumulative updates, Microsoft fixed a vulnerability in its on-premises Exchange servers that allowed attackers to change configuration without authentication. This would have allowed an unauthenticated attacker to change the configuration for mailboxes of arbitrary users. This would have allowed all emails addressed to an email account to be copied and forwarded to an account controlled by the attacker.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Windows 11: PC Health-App updated, release date and no updates for non-compatible systems?

Windows[German]I'm going to summarize some of the Windows 11-related news that has come in here. Microsoft has just updated its PC Health app. With this app, users can check if their hardware is ready for a Windows 11 upgrade. Insiders testing Windows 10 in the Release Preview Channel will also get a hint about a possible upgrade if their hardware is compatible. Microsoft also doesn't want to specifically block the installation of Windows 11 on non-compatible systems, but may stop supplying updates. Furthermore, there are rumored dates when Windows 11 could be officially released.

Continue reading

Posted in Windows | Tagged | 3 Comments

Why you shouldn't use Azure AD Domain Services as a Windows AD replacement

[English]When migrating on-premises Windows servers to the cloud or hybrid solutions, one might get the idea of replacing Windows Active Directory (AD) with Azure AD Domain Services. Should be reconsidered though.

Continue reading

Posted in Cloud, Windows | Tagged , | Leave a comment

Azure App Service: Java 7 support ends July 29, 2022

[English]I don't know if there are people reading this who are responsible for Java support in applications. But in less than a year, support for Java 7 in Microsoft Azure will end. Community support for Java 7 currently ends on July 29, 2022, by which time the move to Java 8 should be complete. Microsoft has alerted users running apps with Java 7 in the Azure cloud to the Java 7 support end date. Apps hosted on App Service will still be able to run, but will no longer receive updates or security patches after community support for Java 7 ends on July 29, 2022. To minimize risk and potential security vulnerabilities, Microsoft recommends updating web apps to Java 11 or 8.

Posted in Cloud | Tagged , | Leave a comment

Exchange Server 2016-2019: Custom attributes in ECP no longer updatable after CU installation (July 2021)

Update[German]The installation of the latest CUs from July 2021 for Microsoft Exchange Server bricks the ability to update custom attributes in the Exchange Control Panel (ECP). That is what some user reports suggest. This affects different on-premises Exchange versions. Here's a brief overview of the issue – I've found so far – a fix from Microsoft isn't known, only a workaround.

Continue reading

Posted in issue, Software | Tagged , , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Windows 10: Upgrades blocked because of old CryptoPro CSP versions

Windows[German]Microsoft has announced in support article KB5006024: Updating to Windows 10, version 2004 or a later version with a certain app installed, that Windows 10 upgrades from version 2004 and higher are currently blocked if old CryptoPro CSP versions are installed on the machine. The reason is compatibility issues with old CryptoPro CSP versions. This is more likely to affect Russian installations, as the CryptoPro CSP applications were developed by a Russian company to access Russian government portals. Bleeping Computer has published some details about it here.

Posted in Update, Windows | Tagged | Leave a comment

Windows 11: Microsoft specifies hardware requirements, no blocking on incompatible devices

Windows[German]Microsoft has specified some requirements for Windows 11 hardware in a blog post. Compared to earlier information, a 7th generation Intel processor was added to the list of compatible devices after all. In addition, it became known that Microsoft does not want to block the installation of Windows 11 via ISO file on incompatible devices.

Continue reading

Posted in Windows | Tagged | 1 Comment

Windows: PrintNightmare wrap-up and status (August 28, 2021)

Windows[German]It's the end of August 2021, and vulnerabilities in the Windows Print Spooler service, collectively known as PrintNightmare, continue to cause problems for administrators. There were security updates for the August 2021 patchday, but they offer more problems than solutions. Therefore, here is a summary as of the end of August 2021.

Continue reading

Posted in issue, Update, Windows | Tagged , | Leave a comment

Master decryptor key published

Sicherheit (Pexels, allgemeine Nutzung)[German]Victims of the Ragnarok ransomware, whose data was encrypted during an attack, can hope again. After the cyber-criminal has just ceased its operations, the master decryptor key has been published. With it, the encrypted files should be able to be restored.

Continue reading

Posted in Security | Tagged , | Leave a comment

Windows 10 V1909: Preview Update KB5005103 (August 26, 2021)

Windows[German]Microsoft has released an optional cumulative (preview) update KB5005103 for Windows 10 version 1909 (Enterprise, Education, IoT) as of August 26. The update fixes various issues with OneDrive and with the Movie and TV apps. Here is an overview of this update.

Continue reading

Posted in Update, Windows | Tagged , | 1 Comment