Tuesday, February 25, 2014

Bromium Researcher's statement on Microsoft EMET - "By 100 percent bypass, we mean all the protections of EMET were enabled, and we bypassed them,"




The research from isn't just purely theoretical, said Kashyap, adding that the techniques the company discovered to bypass EMET can in fact be turned into a weapon by an attacker. Kashyap noted that in Bromium's research paper, a use-after-free vulnerability in Microsoft's Internet Explorer (IE) Web browser that has already been patched, is leveraged to bypass all EMET protections.




The link below has more details:

http://www.eweek.com/security/microsofts-emet-security-technology-isnt-impenetrable-bromium.html

No comments:

Post a Comment