applocker

  1. Understanding CVE-2025-54902: Excel out-of-bounds read may enable RCE; patch and defenses

    A newly disclosed Microsoft Excel vulnerability tracked as CVE-2025-54902 is an out‑of‑bounds read flaw in Excel’s file‑parsing logic that Microsoft warns could allow an attacker to achieve code execution on a targeted machine when a user opens a specially crafted spreadsheet, and organizations...
  2. CVE-2025-54110: Urgent Windows Kernel Patch & Mitigations

    Microsoft has published an advisory for CVE-2025-54110, a Windows Kernel vulnerability caused by an integer overflow or wraparound that can be triggered by a locally authorized attacker to achieve elevation of privilege to SYSTEM on affected machines; administrators should treat this as a...
  3. CIMPLICITY CWE-427: Patch with 2024 SIM 4

    GE Vernova’s CIMPLICITY HMI/SCADA platform has been flagged in a recently circulated advisory as vulnerable to an Uncontrolled Search Path Element (CWE‑427) issue that, under the right local conditions, could allow a low‑privileged user to escalate privileges on affected hosts — the advisory...
  4. AppLockerGen: Open-Source XML Policy Editor for Windows AppLocker

    The arrival of an open-source AppLocker policy generator aimed at simplifying XML policy creation for Windows administrators deserves attention: AppLockerGen promises a lightweight, web-like interface to author, merge, inspect, and export AppLocker policies — but the tool’s appeal comes with...
  5. PC Manager Local Privilege Escalation: Patch, Detect, and Hunt (2025)

    When a vendor-side advisory and a CVE identifier don’t line up, the first — and most important — job for defenders and researchers is to stop, verify, and update the record. I tried to open the MSRC page you gave and could not find any public advisory, nor could I find any authoritative...
  6. CVE-2025-7973: Privilege Escalation in FactoryTalk ViewPoint 14.x

    A critical local privilege‑escalation flaw has been disclosed in Rockwell Automation’s FactoryTalk ViewPoint (versions 14.00 and prior) that allows an attacker with local access to escalate to SYSTEM by abusing Windows MSI repair behavior — the issue is tracked as CVE‑2025‑7973 and has been...
  7. CVE-2025-7973: Privilege Escalation in Rockwell FactoryTalk ViewPoint

    A high-severity privilege-escalation flaw has been disclosed in Rockwell Automation’s FactoryTalk ViewPoint that allows a local attacker to escalate to SYSTEM privileges by abusing Windows MSI repair behavior; the issue (CVE-2025-7973) carries a CVSS v4 base score of 8.5 and affects FactoryTalk...
  8. Siemens DLL Hijacking (CVE-2025-30033) - Mitigations for Web Installer

    Siemens ProductCERT has confirmed a widespread DLL-hijacking flaw in the Siemens Web Installer used by its Online Software Delivery (OSD) mechanism — tracked as CVE‑2025‑30033 — that can allow arbitrary code execution during installation, carries a CVSS v4 base score of 8.5, and affects dozens...
  9. CVE-2025-53718: Windows AFD.sys UAF Privilege Escalation — Patch, Detect, Harden

    Microsoft’s Security Update Guide entry for CVE-2025-53718 describes a use‑after‑free (UAF) flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys) that can be triggered by a locally authorized user to obtain elevated privileges on affected Windows hosts — a kernel‑level...
  10. CVE-2025-50173: Windows Installer Local EoP — What Admins Must Do Now

    Title: CVE‑2025‑50173 — Windows Installer “Weak Authentication” Elevation‑of‑Privilege: What admins need to know and do now Summary Microsoft lists CVE‑2025‑50173 as an elevation‑of‑privilege vulnerability in Windows Installer. The vendor description summarizes the issue as “weak authentication...
  11. Windows Server 2025 Security Hardening: Strategies to Protect Your Infrastructure

    The ongoing digital arms race has placed organizations under relentless pressure to defend their Windows Server infrastructure against an evermore sophisticated array of cyber threats. As cybercriminals refine their tactics, from credential theft to ransomware and lateral movement, Microsoft’s...
  12. Windows 11 24H2 Security Flaw: PowerShell Enforcement Bypass Explained

    A security crisis with broad implications has emerged in recent months as Windows 11 24H2, the much-anticipated feature update, rolled out to users worldwide. Despite Microsoft’s assurances about the readiness and stability of this release, seasoned administrators and cybersecurity professionals...
  13. Microsoft Copilot AI: Challenges, Privacy Risks, and How to Disable It Properly

    Microsoft’s recent introduction of Copilot AI across its ecosystem marks a bold and ambitious shift toward embedding artificial intelligence deeply into productivity software. However, this necessary evolution has not come without its share of controversy, challenges, and user pushback. The...
  14. Releasing Windows 10 Build 19042.1081 (20H2) to Release Preview Channel

    Hello Windows Insiders, today we’re releasing 20H2 Build 19042.1081 (KB5003690)to the Beta and Release Preview Channels for those Insiders who are on 20H2 (Windows 10 October 2020 Update). This update includes the following improvements: This update includes the following improvements: We fixed...
  15. Windows 10 Update for Windows Defender antimalware platform

    Microsoft reports relate to a bogus update from Win Defender stopping some machines from starting when secure boot is turned on:
  16. Announcing Windows 10 Insider Preview Build 16288 for PC & Build 15250 for Mobile

    Hello Windows Insiders! Today we are releasing Windows 10 Insider Preview Build 16288 for PC to Windows Insiders in the Fast ring only (not Skip Ahead). As we mentioned previously, we are now at the point of the development cycle for the Windows 10 Fall Creators Update where our focus is now on...
  17. Microsoft security advisory: Update to improve AppLocker certificate handling: September 8,...

    Link Removed
  18. "Rules cannot be created for the following files" error message in AppLocker when you try to...

    Link Removed
  19. Windows 10 I did not know that.......

    excerpt: There will be two versions of the OS available: Windows 10 Technical Preview and Windows 10 Technical Preview for Enterprise. According to a spokeswoman for Microsoft, both have the same functionality, but the Windows 10 Technical Preview for Enterprise also includes current enterprise...
  20. AppLocker blocks administrators and other high privileged group’s users from executing files...

    Continue reading...