• US-CERT Warns of ASLR Implementation Flaw in Windows 8/8.1 and Windows 10

    The U.S. Computer Emergency Readiness Team is warning of a vulnerability in Microsoft’s implementation of Address Space Layout Randomization that affects Windows 8, Windows 8.1 and Windows 10. The vulnerability could allow a remote attacker to take control of an affected system.

    Microsoft said it is investigating the matter.

    Address Space Layout Randomization (ASLR) is championed as a system hardening technology used in most major desktops and mobile operating systems. ASLR is used to thwart memory-based code-execution attacks. iOS, Android, Windows, macOS and Linux each use ASLR to keep systems safer.

    Read the complete warning here.

    Catalin Cimpanu on bleepingcomputer.com offers a further explanation of the vulnerability and a workaround until Microsoft provides the fix.

    @MrBrian first brought this to our attention on Novemver 17, 2017.
    Please Click here to Comment in the Lounge