Bypassing EMET 4.1

No ratings

Presented at CarolinaCon 2014 by

The goal of the research to be presented was to gauge the difficultly of bypassing the protections offered by EMET, a popular Microsoft zero-day prevention capability. We initially focused on just the ROP protections, but later expanded to all the protections in the real world study. We were able to bypass EMET’s protections in example code and via a real world browser exploit. The two primary novel elements in our research are: 1) Deep study regarding the ROP protections, using example applications 2) Detailed and novel code showing how to defeat the stack pivot protection (SPP), using a real world example. Included in the SPP bypass is an EAF bypass for Windows 7. The impact of this study shows that technologies that operate on the same plane of execution as potentially malicious code, offer little lasting protection.