Microsoft: Heres how were killing a class of memory security bugs in Windows 10

General News

Summary

The Heartbleed vulnerability in the OpenSSL software library for HTTPS web servers was one example of this type of bug, which caused private encryption keys to be stored in uninitialized memory and therefore made it possible for an attacker to retrieve them. The type of memory bug poses a challenge for products with large code bases, in part because of the design of C and C++. Microsoft targeted InitAll at kernel-mode first because of the large number of uninitialized kernel memory vulnerabilities affecting it, while Hyper-V code was prioritized due to recent stack information disclosure bugs. "Now that weve successfully rolled the technology out to the highest priority targets, we can shift our focus to the rest of our code. These drivers were scanning the NT kernel image in memory and looking for byte patterns to locate undocumented functions.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Developer Tools DevOps Software SaaS

Linked Companies

GitHub, Inc.
$1M to $5M
Microsoft
$1B+