Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

Microsoft Launches EMET 5.0

Microsoft announced on Thursday the general availability of the Enhanced Mitigation Experience Toolkit (EMET) 5.0.

Microsoft announced on Thursday the general availability of the Enhanced Mitigation Experience Toolkit (EMET) 5.0.

According to the company, version 5.0 of the free security tool comes with two new mitigations, Attack Surface Reduction (ASR) and Export Address Table Filtering Plus (EAF+), both of which were introduced in EMET 5.0 Technical Preview.

The ASR mitigation is designed to block specific plugins or modules within an application. For instance, companies can use this feature to block Web browsers from loading Java plugins on external websites, while allowing them to work on internal sites. EMET can also be utilized to prevent Microsoft Word from loading Adobe Flash Player, a component which, just like Java, is often exploited in cyberattacks.

The EAF+ mitigation is designed to disrupt advanced attacks with two new safeguards: performing additional integrity checks on stack registers and stack limits when export tables are read from certain lower-level modules, and preventing memory read operations by adding what Microsoft calls “page guard” protection.  The EAF+ started off as an extension to EAF. However, Microsoft says it has made numerous improvements so it has decided to make it a separate mitigation.

In addition to the mitigations, EMET 5.0 brings some other improvements, including the availability of the Deep Hooks, Stack Pivot, Load Library and MemProt Return Oriented Processing (ROP) mitigations on 64-bit platforms. Improvements have also been made to the way EMET terminates untrusted SSL connections with the addition of new “blocking rule” options.

Some of the tasks done by EMET Agent in previous versions of the tool have been picked up by a new feature called EMET Service.

“The EMET Service, among other things, takes care of evaluating the Certificate Trust rules, appropriately dispatching EMET Agents in every user’s instance, and automatically applying Group Policy settings pushed through the network. Also, a service offers more resiliency and better ability to being monitored,” the EMET Team explained in a blog post.

Re there have been several research papers on how to bypass or disarm EMET protections, which is why the latest release has been hardened against such techniques, Microsoft said.

Advertisement. Scroll to continue reading.

Chris Betz, senior director of the Microsoft Security Response Center, revealed that EMET 5.0 also brings some new configuration options to deliver additional flexibility, and new default settings to provide stronger protection immediately after the solution is installed.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.