registry values

Winsage
March 5, 2025
In mid-February 2025, Microsoft updated its support documentation regarding Intel processors' compatibility with Windows 11 24H2, adding several models from the 8th, 9th, and 10th generations that were previously excluded. These processors, introduced about eight years ago, can still perform adequately if their motherboards meet the TPM 2.0 requirement. Microsoft confirmed that these Intel CPU models meet the minimum system requirements for Windows 11 and indicated that future processor generations meeting similar principles will also be considered supported. Although the three Intel generations have not been reinstated on the official list, systems using these processors will not be rendered obsolete or stop receiving updates. Manufacturers are advised against using these older processors in new systems running Windows 11. An official list of supported CPUs for non-OEM or custom PC builders is not available, but builders should refer to Microsoft’s Windows 11 System Requirements, which require a CPU operating at 1 GHz or faster with two or more cores. It is possible to install Windows 11 on unsupported hardware by adjusting certain registry values, but this may result in missing system and security updates. Users can also continue using Windows 10 for ongoing security updates or consider transitioning to a Linux operating system.
Winsage
February 19, 2025
The Windows Registry Editor is accessed by pressing Win-R, typing regedit, and confirming with “OK.” The registry files are located in “C:WindowsSystem32config” and user-specific files in “C:Users[username].” The five main branches of the registry are: - HkeyCurrentUser: Configuration settings for the current user. - HkeyLocalMachine: Global settings for all users, requiring administrative rights for changes. - HkeyUsers: Contains user IDs for system profiles. - HkeyClassesRoot: Manages file name extensions and program shortcuts. - HkeyCurrentConfig: Links to keys under HkeyLocalMachineSystemCurrentControlSetHardware ProfilesCurrent. Users can create subkeys and values, which can be of different types. To modify the registry, select a key, use the “New” context menu, and double-click to edit. Creating a backup of the registry is recommended before making changes, which can be done using the Registry Backup Portable tool. To restore the registry, select the most recent backup and click “Restore Now.” Microsoft’s Process Monitor can be used to analyze registry values by filtering for “RegSetValue” and tracking changes. Certain registry values are restricted from modification for security reasons, such as the “widgets” feature in Windows 11. However, methods like batch files and PowerShell scripts can override these protections. Windows transmits diagnostic data to Microsoft, impacting user privacy. Tools like O&O Shutup10 and W10Privacy help manage telemetry settings.
Winsage
July 29, 2024
Microsoft Outlook has a vulnerability, CVE-2017-11774, that allows for remote code execution through a new framework called "Specula." This vulnerability, a security feature bypass, was patched in October 2017 but can still be exploited in file-sharing attacks. Attackers can create malicious document files to trick users into opening them, and despite Microsoft's mitigation efforts, they can set harmful home pages via Windows Registry values. Specula operates within Outlook's context, allowing non-privileged threat actors to manipulate WebView registry entries to connect to an external server. This enables the execution of arbitrary commands on compromised systems using custom VBScript files. Once the registry entry is set, it can be used for persistence and lateral movement across systems, taking advantage of Outlook's trusted process status to evade security measures. U.S. Cyber Command previously warned about the risks of CVE-2017-11774, which has been exploited by Iranian-sponsored APT groups since at least 2018.
Search