Windows function disables exploit protection

jamescv7

Level 85
Thread author
Verified
Honorary Member
Forum Veteran
Mar 15, 2011
13,070
17,982
8,379
29
Philippines
Security experts Chris Valasek and Ryan Smith have revealed how they are able to bypass Windows' heap-exploitation mitigation feature. They have presented their findings at the hacker conference Infiltrate. Their discovery allowed them to exploit a vulnerability in Internet Information Services (IIS) 7 (since patched) to inject malicious code and prove that Microsoft's initial assessment that exploitation of the vulnerability could at worst only crash the server was wide of the mark.

H-online
 

You may also like...