Vulnerability in Internet Explorer Could Allow Remote Code Execution(technet.microsoft.com)
technet.microsoft.com
Vulnerability in Internet Explorer Could Allow Remote Code Execution
https://technet.microsoft.com/en-US/library/security/2963983
15 comments
No you shouldn't.
1. It breaks a lot of stuff.
2. It isn't very good:
http://bromiumlabs.files.wordpress.com/2014/02/bypassing-eme...
At best it's a dose of Tamiflu.
As many people before have said, you can't retrospectively apply security mitigations properly; you have to design them in from the start.
1. It breaks a lot of stuff.
2. It isn't very good:
http://bromiumlabs.files.wordpress.com/2014/02/bypassing-eme...
At best it's a dose of Tamiflu.
As many people before have said, you can't retrospectively apply security mitigations properly; you have to design them in from the start.
Who said to apply EMET to "a lot of stuff"?
It is meant to plug holes in apps that handle untrusted data. For a vast majority of people that would be a browser, a mail client and various document viewers. IE, Firefox, Chrome, Flash player, Outlook, Thunderbird and Acrobat Reader all run A-Ok under EMET and most of them are on its default list.
Remeber the RTF zeroday from a couple weeks ago? It too was mitigated with EMET. That's two zerodays in two weeks.
The Bromium labs bypass was addressed in EMET 5.0, not few weeks after their announcement.
The bottom line is that it the most effective zeroday protection available at the moment. Is it perfect? No. Does it work? Yes.
It is meant to plug holes in apps that handle untrusted data. For a vast majority of people that would be a browser, a mail client and various document viewers. IE, Firefox, Chrome, Flash player, Outlook, Thunderbird and Acrobat Reader all run A-Ok under EMET and most of them are on its default list.
Remeber the RTF zeroday from a couple weeks ago? It too was mitigated with EMET. That's two zerodays in two weeks.
The Bromium labs bypass was addressed in EMET 5.0, not few weeks after their announcement.
The bottom line is that it the most effective zeroday protection available at the moment. Is it perfect? No. Does it work? Yes.
1. Really? I've been using it for a while, and no breakage. Sure, I just use the default rulelist instead of applying rules to everything (which imo is what most people should do).
2. Sure, but it's better than nothing. As parent said, this exploit is mitigated by EMET. See http://rationallyparanoid.com/articles/emet-testing.html for more tests
Yes, it's a bandaid. But since it help and it's free, why not?
2. Sure, but it's better than nothing. As parent said, this exploit is mitigated by EMET. See http://rationallyparanoid.com/articles/emet-testing.html for more tests
Yes, it's a bandaid. But since it help and it's free, why not?
We've had a couple of older COM-based applications that target Windows 5.1 (2003/XP) platforms fail unpredictably with it on later operating systems. Whether these are just badly behaved applications or compilers or a faulty design in EMET we don't know as it's all closed source and when you're left with a steaming minidump (because you can't catch these unless you use ADplus) it's not easy to work out why a process failed from that if EMET shot it.
As for the better than nothing, yes until your phone starts ringing like a cheesy sci-fi flick because half your MSMQ sinks are crashing...
My comment above probable shouldn't have been: no you shouldn't use it until you've soak tested your applications on it.
As for the better than nothing, yes until your phone starts ringing like a cheesy sci-fi flick because half your MSMQ sinks are crashing...
My comment above probable shouldn't have been: no you shouldn't use it until you've soak tested your applications on it.
EMET should show a notification when it blocks something and it should also make an event log entry. (These are configurable iirc.)
Terrible advice. You should definitely run EMET.
The subtitle has the meat: "Vulnerability in Internet Explorer Could Allow Remote Code Execution".
"Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in [IE 6 through 11]." --date published: April 26, 2014.
"Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in [IE 6 through 11]." --date published: April 26, 2014.
I think remote code execution and the easy method for payload delivery warrants a high level of concern.
It seems from the subtitle that this isn't just a known vulnerability, but one being exploited in the wild, if I'm not mistaken. Definitely a serious concern either way though.
XP is absent from the list of affected OSes. Does that mean XP isn't affected, or is it just off the radar now that it's no longer supported.
Could this be the first big unpatched XP hole?
Could this be the first big unpatched XP hole?
Isn't there an extended, for-pay support service for xp? In that case, it must mean a patch will be engineered and released to paying customers. How long until these leak out and pirates start trading XP patches?
How long until people start offering unofficial patches that include backdoors?
I think XP is affected. Luckily the current exploits only works on IE9-11, excluding XP.
Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11.
I'm pretty sure this will affect XP as a result.
I'm pretty sure this will affect XP as a result.
If you are on Windows and you are not running EMET, you should really drop everything right now and install it.
http://www.microsoft.com/emet