Vulnerability in Internet Explorer Could Allow Remote Code Execution
technet.microsoft.com
technet.microsoft.com
If you are on Windows and you are not running EMET, you should really drop everything right now and install it.
1. It breaks a lot of stuff.
2. It isn't very good:
http://bromiumlabs.files.wordpress.com/2014/02/bypassing-eme...
At best it's a dose of Tamiflu.
As many people before have said, you can't retrospectively apply security mitigations properly; you have to design them in from the start.
2. Sure, but it's better than nothing. As parent said, this exploit is mitigated by EMET. See http://rationallyparanoid.com/articles/emet-testing.html for more tests
Yes, it's a bandaid. But since it help and it's free, why not?
As for the better than nothing, yes until your phone starts ringing like a cheesy sci-fi flick because half your MSMQ sinks are crashing...
My comment above probable shouldn't have been: no you shouldn't use it until you've soak tested your applications on it.
It is meant to plug holes in apps that handle untrusted data. For a vast majority of people that would be a browser, a mail client and various document viewers. IE, Firefox, Chrome, Flash player, Outlook, Thunderbird and Acrobat Reader all run A-Ok under EMET and most of them are on its default list.
Remeber the RTF zeroday from a couple weeks ago? It too was mitigated with EMET. That's two zerodays in two weeks.
The Bromium labs bypass was addressed in EMET 5.0, not few weeks after their announcement.
The bottom line is that it the most effective zeroday protection available at the moment. Is it perfect? No. Does it work? Yes.
"Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in [IE 6 through 11]." --date published: April 26, 2014.
Could this be the first big unpatched XP hole?
I'm pretty sure this will affect XP as a result.