Mitigations

Standing behind “MSRC Listens”

Last week at BlueHat’s “MSRC Listens” session, I took the stage with Mechele Gruhn, manager of the Vulnerability Response PM team, to explain how MSRC is changing our communication, workflows, and tooling to deliver an improved user experience for our partners in the security research community. We promised to communicate more about what’s happening in …

Standing behind “MSRC Listens” Read More »

Windows 10: 強化された脆弱性緩和技術で攻撃のコストを上げる

システムやアプリケーションの脆弱性を悪用し、不正なコードと置き換えて実行させるのは典型的な攻撃手法の 1 つですが、この場合、脆弱性を足がかりに、追加のマルウェアのインストールなどが行われ、結果的にコンピューターを好きなように操作されてしまいます。脆弱性にはセキュリティ更新プログラムを適用するのが最善策ですが、必ずしもすぐに適用できなかったり、ゼロデイのようにセキュリティ パッチが作成される前に攻撃が実行される場合もあります。   そのような状況からシステムを保護するために、Windows 10 では、実効性のある攻撃コードの開発を困難にするための、より強化された機能が搭載されています。   強化された脆弱性緩和機能 脅威に対する耐性の 1 つとして、また攻撃コストを高めるため、Windows には、脆弱性を悪用した不正なコード実行を防ぐ (困難にする) いくつかの緩和機能が搭載されています。Windows のバージョンを重ねるごとに、そのときどきの悪用手法に対抗する機能が追加、強化されており、Windows 10 では、新たな機能として制御フロー ガードという緩和機能が追加されました。     Windows 2003 以前 Windows XP SP2 Windows Vista/7 Windows 8 Windows 10 追加/強化された機能 特になし DEP /GS SafeSEH Heap hardening v1   ASLR v1 SEHOP Heap hardening v2   ASLR v2 Kernel SMEP & …

Windows 10: 強化された脆弱性緩和技術で攻撃のコストを上げる Read More »

EMET 5.2 is available (update)

Today, we’re releasing the Enhanced Mitigation Experience Toolkit (EMET) 5.2, which includes increased security protections to improve your security posture. You can download EMET 5.2 from microsoft.com/emet or directly from here. Following is the list of the main changes and improvements: Control Flow Guard: EMET’s native DLLs have been compiled with Control Flow Guard (CFG). …

EMET 5.2 is available (update) Read More »

Assessing risk for the August 2014 security updates

Today we released nine security bulletins addressing 37 unique CVE’s. Two bulletins have a maximum severity rating of Critical while the other seven have a maximum severity rating of Important. This table is designed to help you prioritize the deployment of updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max …

Assessing risk for the August 2014 security updates Read More »

General Availability for Enhanced Mitigation Experience Toolkit (EMET) 5.0

Today, we are excited to announce the general availability of Enhanced Mitigation Experience Toolkit (EMET) 5.0. EMET is a free tool, designed to help customers with their defense in depth strategies against cyberattacks, by helping block and terminate the most common techniques adversaries might use in comprising systems. EMET 5.0 further helps to protect with …

General Availability for Enhanced Mitigation Experience Toolkit (EMET) 5.0 Read More »

Assessing risk for the June 2014 security updates

Today we released seven security bulletins addressing 66 unique CVE’s.  Two bulletins have a maximum severity rating of Critical while the other five have a maximum severity rating of Important. This table is designed to help you prioritize the deployment of updates appropriately for your environment. Bulletin         Most likely attack vector Max Bulletin Severity Max …

Assessing risk for the June 2014 security updates Read More »

Assessing risk for the May 2014 security updates

Today we released eight security bulletins addressing 13 unique CVE’s. Two bulletins have a maximum severity rating of Critical while the other six have a maximum severity rating of Important. The table is designed to help you prioritize the deployment of updates appropriately for your environment. Bulletin Most likely attack vector Max Bulletin Severity Max …

Assessing risk for the May 2014 security updates Read More »

Protection strategies for the Security Advisory 2963983 IE 0day

We’ve received a number of customer inquiries about the workaround steps documented in Security Advisory 2963983 published on Saturday evening. We hope this blog post answers those questions. Steps you can take to stay safe The security advisory lists several options customers can take to stay safe. Those options are (in summary): Deploy the Enhanced …

Protection strategies for the Security Advisory 2963983 IE 0day Read More »

CVE-2013-3893: Fix it workaround available

Today, we released a Fix it workaround tool to address a new IE vulnerability that had been actively exploited in extremely limited, targeted attacks.  This Fix it makes a minor modification to mshtml.dll when it is loaded in memory to address the vulnerability. This Fix it workaround tool is linked from Security Advisory 2887505 that describes this …

CVE-2013-3893: Fix it workaround available Read More »

August 2013 Security Bulletin Webcast, Q&A, and Slide Deck

Today we’re publishing the August 2013 Security Bulletin Webcast Questions & Answers page.  We fielded 13 questions on various topics during the webcast, with specific bulletin questions focusing primarily on Exchange Server (MS13-061) and Windows Kernel (MS13-063).  There were 3 additional questions during the webcast that we were unable to answer on air, and we …

August 2013 Security Bulletin Webcast, Q&A, and Slide Deck Read More »