CVE-2021-26900: Privilege Escalation Via a Use After Free Vulnerability In win32k

CVE-2021-26900: Privilege Escalation Via a Use After Free Vulnerability In win32k https://ift.tt/33c9EGX In March 2021, Microsoft released a patch to correct a vulnerability in the Windows kernel. The bug could allow an attacker to execute code with escalated privileges. This vulnerability was reported to the ZDI program by security researcher JeongOh Kyea (@kkokkokye) of THEORI. […]

Security baseline for Microsoft 365 Apps for enterprise v2104 – FINAL

Security baseline for Microsoft 365 Apps for enterprise v2104 – FINAL https://ift.tt/3eIK2GS Microsoft is pleased to announce the final release of the recommended security configuration baseline settings for Microsoft 365 Apps for enterprise, version 2104. Please download the content from the Microsoft Security Compliance Toolkit, test the recommended configurations, and implement as appropriate. If you […]

Securing Active Directory: How to Prevent the SDProp and adminSDHolder Attack

Securing Active Directory: How to Prevent the SDProp and adminSDHolder Attack https://ift.tt/3vpMU2k Attackers can get into your Active Directory by leveraging the SDProp process and gaining privileges through the adminSDHolder object. Here’s how to stop them. Attackers use every possible trick and process they can to get into your Active Directory environment by moving laterally […]

How to Migrate to Office 365 the Secure Way

How to Migrate to Office 365 the Secure Way https://ift.tt/3uaEQC0 Looking to extend your Active Directory to the cloud? This guide explores options for securely migrating your on-prem identities and access controls to Office 365.  Cloud computing offers lower costs, better flexibility and greater capacity beyond the limited resources most organizations have in their data […]