Microsoft EMET 5.2 with Control Flow Guard now available

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
Microsoft's Enhanced Mitigation Experience Toolkit is one of the programs that I install on Windows PCs that I set up for myself or others.

The program attempts to block exploits from successfully running on Windows machines. The most likely scenario where this happens is when attacks managed to sneak past system defenses.

Without EMET, these attacks would be successful whereas you still have a chance of blocking them with EMET.

While EMET is not a catch-all solution that protects you from every piece of malicious code out there, it is not using lots of system resources and adds another layer of protection to Windows machines.

Microsoft has just released EMET 5.2, a new version of the Enhanced Mitigation Experience Toolkit that updates the previous version 5.1.

Note that thecompany offerstwo different versions of EMET right now. First the 5.2 version which is the latest, and then version 4.1 Update 1 which it will support until June 9, 2015.

So what is new in EMET 5.2?



Microsoft EMET 5.2 ships with three new features of which two enhance the protection on all supported operating systems and one only on Windows 8 and newer versions.

All EMET installations benefit from Control Flow Guard, a new feature of Visual Studio 2015, that "helps detect and stop attempts of code hijacking". Control Flow Guard is only supported by Windows 8.1 and newer versions of Windows including Windows 10 which means that it benefits only systems that run these operating systems.

The second change improves the program's Attack Surface Reduction mitigation which tries to "stop attempts to run the VBScript extension" when loaded in the Internet Zone of Internet Explorer. According to Microsoft, this protects against the exploitation technique known as VBScript God Mode.

The third and final change affects Internet Explorer as well. EMET supports alerting and reporting with Enhanced Protected Mode enabled from desktop Internet Explorer and Modern Internet Explorer now.

You can download the EMET from the official Microsoft website linked above. It is suggested currently to use the direct linkposted in the blog poston the Microsoft Security Research and Defense Blog as the main download site seems to be broken currently.

The installer upgrades existing versions of EMET on the system and also installs the software anew if it has not been installed on the system before.
Source
 

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,144
Although EMET is a useful addition to the security setup of Windows, I would just like to clarify one thing that may lead to unwarranted expectations, namely the VBScript God Mode (more correctly OLE Automation Array Remote Code Execution) protection. Please note that of the major browsers used, only IE allows the running of VB scripts through a legacy engine. Seamonkey, Firefox, and Chrome do not support the running of these scripts. Actually with IE11 vb scripts aren't really supported, but VBScript does still execute for legacy document modes still.

This added protection is actually a patch of previous versions of EMET (which was bypassed) than anything truly novel.
 
Last edited:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top