The EMET (Enhanced Mitigation Experience Toolkit) tool developed by Microsoft makes it possible for administrators and end users to retroactively equip applications with additional protection mechanisms. This enhanced protection is intended to prevent various attack techniques that are currently used by cyber attackers.
Security expert René Freingruber of the SEC Consult Vulnerability Lab has developed numerous methods to get around the basic protection mechanisms of EMET in all currently available versions. If a cyber-attacker were to use these new bypass methods, serious attacks could be carried out. A software product protected with EMET as a workaround affected by a critical zero-day vulnerability could, for example, fall under the control of attackers.
Microsoft was informed of this by SEC Consult and is working on an improvement to the protection methods.
The experts of the SEC Consult Vulnerability Lab advise you to not view EMET as an unbeatable protection measure, because the tool can definitely be bypassed with the help of newly discovered methods.
SEC Consult considers it as necessary for software manufacturers to make the development of applications more secure and to regularly test their software extensively for application security.
- A video demonstrating the issues has been released: http://youtu.be/TuBQnvnKKHY
Detailed slides from previous conferences, where the research has been presented by René Freingruber, are available here:
RuxCon, 11-12 October 2014
- Short bio/description: https://ruxcon.org.au/speakers/#Ren%C3%A9%20Freingruber
- Slides: http://prezi.com/z0kjt1wi_9nl/ruxcon-2014-emet-50-armor-or-curtain/
ToorCon, 25-26 October 2014
- Short bio/description: http://sandiego.toorcon.net/conference/#7
- Slides: http://prezi.com/qodsslaplj7j/toorcon-2014-emet-50-armor-or-curtain/
ZeroNights, 13-14 November, 2014
- Short bio/description: http://2014.zeronights.org/conference/speakers.html#freingruber
- Slides: https://prezi.com/tnqeqis3vhum/zeronights-2014-emet-51-armor-or-curtain/
- Video: https://youtu.be/H-wPdv84K6A
NorthSec 21-24 May, 2015
- Video: https://youtu.be/LWRKopVm8yo
- Video: https://youtu.be/2-w19wMw0aI
- Security Research and Defense Blog: http://blogs.technet.com/b/srd/archive/2014/11/10/emet-5-1-is-available.aspx
- SEC Consult bypassed EMET 5.1 again. More technical details follow @DeepSec 2014