| Use EMET 2.0 to block Adobe Reader and Acrobat 0-day exploit |
| Written by Stewart Smith | |||
| Sunday, 12 September 2010 18:43 | |||
|
As you probably know there is a new exploit in the wild for Adobe Reader and Acrobat. This particular exploit is using the Return Oriented Programming (ROP) exploit technique in order to bypass Data Execution Prevention (DEP). [...] The good news is that if you have the Enhanced Mitigation Experience Toolkit 2.0 (EMET) enabled for AcroRd32.exe, it blocks this exploit. This happens thanks to two different mitigations...
|
| --BEGIN GEEK CODE BLOCK-- GE/CS d++ s:++>: a+ C++ LU--- P++ L+ E---W++(+) N++ o-- K w++ O--- M-- V PS PE Y PGP- t++ 5X++ R->$ tv- b+ DI++ D G+ e++ h--- r+++ z+++ --END GEEK CODE BLOCK-- |