• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / tweaks / ASLR vulnerability in Windows 8, 10: fix directly

ASLR vulnerability in Windows 8, 10: fix directly

20/11/2017 18:14 by giorgos

Address Space Layout Randomization or ASLR: Windows 8, Windows 8.1 and later versions of Windows 10 are reported to be incorrectly implementing ASLR, making us a very critical security feature of Windows.

Address Space Layout Randomization or ASLR is a security technique that selects random memory addresses to run the code of an application.

  • Windows 10: The Great Journey of Paid Reliability

The ASLR feature was originally released in 2003 in OpenBSD and has since been added to all major operating systems, Linux, Android, MacOS, and Windows.

Microsoft has first added ASLR to Windows with 2006 Vista. To enable the feature, users had to install Microsoft EMET and use their GUI to choose to use ASLR in system-wide or application-specific situations.

With the release of Windows 10, ASLR was added to Windows Defender Exploit Guard and users can activate it through the Windows Defender Security Center.

aslr - ASLR Vulnerability in Windows 8, 10: Fix Immediately

A vulnerability that exists here and 17 years (was recently revealed) that affects the Microsoft Office equation editor, demonstrated that ASLR did not randomize memory code addresses into application files under certain conditions.

According to Will Dormann, a CERT / CC vulnerability analyzer, when users activate ASLR protection across the system, there were errors that did not allow the creation of random memory addresses.

"The result is that programs used the same address every time on all reboots even on different systems," Dormann said in a statement. published in CERT.

This in practice means that the ASLR is not used though it is turned on, which means that the security feature users are open to attacks of re-using memory addresses of an application containing malicious code.

The researcher says that this issue only affects Microsoft systems from Windows 8 and then because the company changed the registry values ​​through which the ASLR starts.

Of course Microsoft is expected to fix the problem in some future update and for now, the only way to boot the ASLR feature to work is a tweak oscillation in the Windows registry.

How can I protect:

Create a text file and type the following text:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Control \ Session Manager \ kernel]
"MitigationOptions"=hex:00,01,01,00,00,00,00,00,00,00,00,00,00,00,00,00

Save the .reg file instead of .txt, for example, iguru.reg.

Optionally, you can download the file we made for you, and run it with a double click (after exporting it from .zip)

Right click save as:

iguru.reg

ASLR vulnerability in Windows 8, 10: fix directly was last modified: 20 November, 2017, 6: 14 pm by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: tweakstag: 2003, android, click, I'm sure, Microsoft Windows

You May Also Like

Adware: How can it steal your personal data?
7 Android applications that act as a remote control for your computer
Google: how do we improve Android security?

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « qBittorrent 4 BitTorrent for all platforms
Next Post: Quad9 DNS free of charge from IBM X-Force »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.