Microsoft disables BitLocker security fix, advises manual mitigation

August 15, 2024 at 11:34AM Microsoft disabled a BitLocker vulnerability fix due to firmware incompatibility, causing devices to enter recovery mode. The CVE-2024-38058 flaw allows attackers to bypass BitLocker encryption and access data. To mitigate the issue, users must follow a complex 4-stage process and may face limitations. Microsoft didn’t address the root cause, urging … Read more

Microsoft retires Windows updates causing 0x80070643 errors

August 14, 2024 at 02:31PM Microsoft has retired Windows security updates from January 2024 Patch Tuesday due to 0x80070643 errors when installing WinRE updates. The company acknowledged the issue in January, caused by problematic KB5034441, KB5034440, and KB5034439 updates. After months of investigation, Microsoft announced no automated fix, instead advising users to manually expand their … Read more

Microsoft Issues Patches for 90 Flaws, Including 10 Critical Zero-Day Exploits

August 14, 2024 at 02:03AM Microsoft shipped fixes for 90 security flaws, including 10 zero-days with active exploitation. Notable updates include addressing CVE-2024-38189, 38178, 38193, 38106, 38107, and 38213. Furthermore, CISA added the flaws to its Known Exploited Vulnerabilities catalog. The update from Microsoft also includes addressing CVE-2024-38200, 38199, 21302, and 38198. Other vendors have … Read more

Windows 11 KB5041585 cumulative update released with fixes, new features

August 13, 2024 at 01:38PM Microsoft has launched the KB5041585 cumulative update for Windows 11 23H2, bringing various enhancements and changes. Notably, this update enables users to drag apps directly from the Pinned section of the Start menu and pin them to the taskbar. Based on the meeting notes, the main takeaway is that Microsoft … Read more

Windows 10 KB5041580 update released with 14 fixes, security updates

August 13, 2024 at 01:23PM Microsoft has launched the KB5041580 cumulative update for Windows 10 22H2 and 21H2, incorporating 14 changes and fixes, notably addressing BitLocker issues and providing critical security updates. It looks like you have provided the meeting notes about the release of the KB5041580 cumulative update for Windows 10 22H2 and Windows … Read more

Microsoft is killing the Windows Paint 3D app after 8 years

August 12, 2024 at 03:21PM Microsoft announced the discontinuation and removal of the Paint 3D graphics app from the Microsoft Store in November. Based on the meeting notes, the key takeaway is that Microsoft has announced the discontinuation of the Paint 3D graphics app, which will be removed from the Microsoft Store in November. Full … Read more

Microsoft Warns of OpenVPN Vulnerabilities, Potential for Exploit Chains

August 12, 2024 at 11:54AM Microsoft revealed multiple vulnerabilities in OpenVPN at the Black Hat security conference. These flaws, now fixed in OpenVPN 2.6.10, could be combined by skilled attackers to gain control of targeted systems. Exploitation requires user authentication and a deep understanding of OpenVPN. Users are strongly advised to apply the available fixes. … Read more

Microsoft: Windows 11 22H2 reaches end of support in 60 days

August 10, 2024 at 12:28PM Microsoft has announced that multiple editions of Windows 11 21H2 and 22H2 will no longer receive updates after October 8, 2024. This affects various editions including Home, Pro, Pro Education, and Pro for Workstations. Windows Update will automatically initiate a feature update to keep devices secure and productive. Customers can … Read more

Microsoft discloses unpatched Office flaw that exposes NTLM hashes

August 10, 2024 at 12:28PM Microsoft disclosed a high-severity vulnerability affecting multiple Office versions, including Office 2016 and Microsoft 365 Apps for Enterprise. Tracked as CVE-2024-38200, the flaw allows unauthorized access to protected information. Although Microsoft is developing security updates, an alternative fix has been released. Blocking outbound NTLM traffic is recommended as a mitigation. … Read more

Microsoft Reveals Four OpenVPN Flaws Leading to Potential RCE and LPE

August 9, 2024 at 02:51PM Microsoft disclosed medium-severity security flaws in OpenVPN, enabling attackers to achieve remote code execution and local privilege escalation. The vulnerabilities, affecting versions prior to 2.6.10 and 2.5.10, can lead to data breaches and system compromise. Exploitation requires user authentication and advanced understanding of OpenVPN’s inner workings. Vulnerabilities can be exploited … Read more