
Microsoft's antimalware 'EMET' is vulnerable to 'inside-out' cyberattacks
Microsoft often swears that its Enhanced Mitigation Experience Toolkit (EMET) protects businesses and users from malware, but two researchers have found that EMET has a serious security vulnerability that could allow hackers to use the antimalware software against itself.
Earlier this week, researchers at FireEye revealed that previous versions of EMET have a key security flaw that allows hackers to use the free security tool to disable it. Security experts Abdulelah Al Saheel and Raghav Pande discovered that the part of the EMET code responsible for downloading the software can be used to completely disable EMET, rendering the antimalware software completely useless.
They also revealed that they have worked with Microsoft ahead of the launch of EMET version 5.5 this month to create a patch that will address this security threat. So, the security vulnerability cannot be exploited in the latest version of EMET, but older versions, including 5.0, 5.1, and 5.2 that Microsoft still supports, are not secure. In addition to this patch, Emet 5.5 boasts additional support for Windows 10 and a number of other improvements.
The researchers and Microsoft urged users to upgrade to the latest version of EMET.
Additionally, EMET can protect against some, but not all, zero-day vulnerabilities. So, EMET can "detect and block exploit techniques commonly used for memory corruption vulnerabilities," but it alone cannot provide complete security. The free tool is intended to be just one way to add additional barriers to malware attacks.
The fact that various versions of EMET could be bypassed or disabled by attackers has been known for many years. In 2014, researchers at Bromium Labs showed that they had found a way to bypass EMET 4.1. Despite this, EMET remains a popular tool for Microsoft users, especially due to the fact that Microsoft provides the software for free.
