
The Russian company Positive Research has discovered a vulnerability in the Microsoft Windows 8 RTM version of the new operating system, the output of which is planned on October 26, 2012. Specialists found the opportunity to bypass the recently represented Intel SMEP protection technology, reports DailyComm .
The Intel SMEP protection tool was first implemented in Intel processors based on the Ivy Bridge architecture, which appeared on the market in April 2012. The technology involves a significant complication of the execution of malicious code in a privileged mode and protects the system from a number of possible attacks.
However, with an incorrect configuration of the X86 of the Windows 8 versions, the attacker can get the opportunity to bypass Intel SMEP security, using the shortcomings of protection mechanisms in 32-bit versions of Windows 8 and received information about the targeted space of the OS.
Experts also found that the 64-bit version of Windows 8 is safer, but it is currently also vulnerable. Experts of the Positive Research research center demonstrated bypassing protection on this OS using the “Return-Oriented Programming, ROP), and also found out that during operation of third-party drivers, another potential method for detaching SMEP protection is possible.
This class of vulnerabilities is the most dangerous, since when successful operation of the nucleus mode, the attacker receives full control over the attacking system, without any restrictions on OS security.
The other day, we recall, it became known that Microsoft has not yet been updated by the Internet Explorer 10 browser in Windows 8, which contains a critical vulnerability in the built -in adobe Flash Player plugin. The software giant only promises to provide users with the appropriate update by October 26, 2012, that is, two months after Adobe itself was released for the player.
According to the representative of Adobe, Microsoft postponed the renewal output, since the "updates" channel for the new OS has not yet been working.