Vertrouw jij op troubleshooter-tools van Windows? Die gaan er op termijn uit!
https://agconnect.nl/artikel/microsoft-gooit-eigen-diagnostische-tools-op-de-schop-voor-security
#MSDT
Vor rund vier Wochen war durchgesickert, dass #Microsoft das sogenannte "Microsoft Support Diagnostic Tool", kurz #MSDT, einstampfen will. Nun hat der Konzern diese Gerüchte bestätigt. https://winfuture.de/news,134475.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
#Microsoft plant allen Anschein nach, das Microsoft Support Diagnostic Tool, kurz #MSDT, komplett einzustellen. https://winfuture.de/news,134039.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
Microsoft Patch Tuesday, June 2022 Edition
https://krebsonsecurity.com/2022/06/microsoft-patch-tuesday-june-2022-edition/
#MicrosoftSupportDiagnosticsTool #MicrosoftPatchTuesdayJune2022 #TrendMicroZeroDayInitiative #CVE-2022-30190 #KevinBeaumont #AzureSynapse #MayureshDani #OrcaSecurity #TimetoPatch #AmitYoran #Follina #Tenable #MSDT
#MicrosoftSupportDiagnosticsTool #MicrosoftPatchTuesdayJune2022 #TrendMicroZeroDayInitiative #CVE #KevinBeaumont #AzureSynapse #MayureshDani #OrcaSecurity #TimetoPatch #AmitYoran #follina #Tenable #msdt
Microsoft Patch Tuesday, June 2022 Edition https://krebsonsecurity.com/2022/06/microsoft-patch-tuesday-june-2022-edition/ #MicrosoftSupportDiagnosticsTool #MicrosoftPatchTuesdayJune2022 #TrendMicroZeroDayInitiative #CVE-2022-30190 #KevinBeaumont #AzureSynapse #MayureshDani #OrcaSecurity #TimetoPatch #AmitYoran #Follina #Tenable #MSDT
#microsoftsupportdiagnosticstool #microsoftpatchtuesdayjune2022 #TrendMicroZeroDayInitiative #CVE #KevinBeaumont #AzureSynapse #mayureshdani #OrcaSecurity #TimetoPatch #amityoran #follina #Tenable #msdt
Microsoft Patch Tuesday, June 2022 Edition - Microsoft on Tuesday released software updates to fix 60 security vulnerabilities ... https://krebsonsecurity.com/2022/06/microsoft-patch-tuesday-june-2022-edition/ #microsoftsupportdiagnosticstool #microsoftpatchtuesdayjune2022 #trendmicrozerodayinitiative #cve-2022-30190 #kevinbeaumont #azuresynapse #mayureshdani #orcasecurity #timetopatch #amityoran #follina #tenable #msdt
#msdt #tenable #follina #amityoran #timetopatch #orcasecurity #mayureshdani #azuresynapse #kevinbeaumont #cve #trendmicrozerodayinitiative #microsoftpatchtuesdayjune2022 #microsoftsupportdiagnosticstool
Besides #Follina, there is a second #Dogwalk vulnerability in #Windows - related to #MSDT - is not fixed. But there is a #0patch micro patch to fix that.
https://borncity.com/win/2022/06/10/windows-msdt-0-day-schwachstelle-dogwalk-erhlt-0patch-fix/
#0patch #msdt #windows #dogwalk #Follina
Gibt neben #Follina noch eine zweite #Dogwalk genannte #Schwachstelle in #Windows - in Verbindung mit #MSDT - wird nicht gefixt. Aber es gibt einen #0patch Micro-Patch.
https://www.borncity.com/blog/2022/06/10/windows-msdt-0-day-schwachstelle-dogwalk-erhlt-0patch-fix/
#0patch #msdt #windows #schwachstelle #dogwalk #Follina
Besser wird’s nicht: #msdt führt auf Windows-PCs Powershell-Skripte aus, die in eine URL eingebettet sind. Ein Klick zum Untergang:
https://www.huntress.com/blog/microsoft-office-remote-code-execution-follina-msdt-bug
Der Angriff des Killertaschenrechners.
#msdt #microsoft https://www.heise.de/forum/heise-online/Kommentare/Zero-Day-Luecke-in-MS-Office-Microsoft-gibt-Empfehlungen/Entwarnung-Defender-blockiert-jetzt-calc-exe/posting-41075231/show/
Da hatte ich immer geglaubt, der Code des Microsoft-Diagnosewerkzeugs bestünde nur aus einer Warteschleife und der Textbox „wir konnten das Problem nicht beheben“ und jetzt stellt sich heraus, dass #msdt doch eine Funktion hat: https://www.heise.de/news/Zero-Day-Luecke-in-MS-Office-Microsoft-gibt-Empfehlungen-7126993.html
Mysterious “Follina” zero-day hole in Office – what to do? - News has emerged of a "feature" in Office that has been abused as a zero-day bug to run e... https://nakedsecurity.sophos.com/2022/05/31/mysterious-follina-zero-day-hole-in-office-what-to-do/ #securitythreats #vulnerability #microsoft #follina #ms-msdt #zeroday #office #msdt
#msdt #office #zeroday #ms #follina #microsoft #vulnerability #securitythreats
RT @sans_isc@twitter.com
The #msdt 0-day currently being exploited can be blocked by removing the handler. Note that this may block legit uses (but not sure there are any/enough to not apply this workaround). https://twitter.com/DidierStevens/status/1531033449561264128