Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

Microsoft Expert Discovered a Series of Serious Code

Explore Microsoft expert discovered a series of serious code with clear explanations, useful context, practical examples, and actionable tips that are.

Table of Contents

This guide provides a clear, practical overview of Microsoft expert discovered a series of serious code, with useful context, important details, and straightforward takeaways for everyday readers.

Microsoft security team found these 25 BadAlloc vulnerabilities in a cluster of standard memory allocation functions widely used in many real-time operating systems (RTOS), standard deployment libraries. standard C (libc) and embedded software development kit (SDK).

" Our research shows that many memory allocation implementations written over the years as part of IoT devices and embedded software have failed to incorporate input authentications. appropriate , "said a team representative from the Microsoft Security Response Center. " Without these input validations, an attacker could fully exploit the memory allocation function to perform a heap overflow, leading to remote execution of malicious code. on target device ".

Microsoft Expert Discovered a Series of Serious Code

BadAlloc vulnerable devices

The majority of IoT and OT devices that are susceptible to the aforementioned BadAlloc vulnerabilities are currently widely used in the consumer, medical and industrial networking sectors.

The complete list of devices affected by BadAlloc includes:

  • Amazon FreeRTOS, Version 10.4.1
  • Apache Nuttx OS, Version 9.1.0
  • ARM CMSIS-RTOS2, versions prior to 2.1.3
  • ARM Mbed OS, version 6.3.0
  • ARM mbed-uallaoc, Version 1.3.0
  • Cesanta Software Mongoose OS, v2.17.0
  • eCosCentric eCosPro RTOS, Versions 2.0.1 to 4.5.3
  • Google Cloud IoT Device SDK, Version 1.0.2
  • Linux Zephyr RTOS, versions prior to 2.4.0
  • Media Tek LinkIt SDK, previous versions 4.6.1
  • Micrium OS, Version 5.10.1 and earlier
  • Micrium uCOS II / uCOS III Version 1.39.0 and earlier
  • NXP MCUXpresso SDK, previous versions 2.8.2
  • NXP MQX, Version 5.1 and earlier
  • Redhat newlib, previous versions 4.0.0
  • RIOT OS, Version 2020.01.1
  • Samsung Tizen RT RTOS, previous version 3.0.GBB
  • TencentOS-tiny, Version 3.1.0
  • Texas Instruments CC32XX, previous versions 4.40.00.07
  • Texas Instruments SimpleLink MSP432E4XX
  • Texas Instruments SimpleLink-CC13XX, versions prior to 4.40.00
  • Texas Instruments SimpleLink-CC26XX, versions prior to 4.40.00
  • Texas Instruments SimpleLink-CC32XX, versions prior to 4.10.03
  • Uclibc-NG, previous versions 1.0.36
  • Windriver VxWorks, before 7.0

To minimize risk, organizations using a BadAlloc vulnerable device should:

  • Apply carrier updates available.
  • Minimize the network exposure of all devices or control systems, and ensure that they are not accessible from the Internet.
  • Locate the control system network and remote devices behind the firewall, and isolate them from the corporate network.
  • When remote access is required, use secure methods, such as virtual private network (VPN).

If vulnerable devices cannot be patched immediately, Microsoft recommends:

  • Narrow the attack surface by minimizing or eliminating the vulnerable devices' exposure to the internet;
  • Perform network security monitoring to detect indicators of intrusion;
  • Strengthen network segmentation to protect important data.

Key Takeaways

Use the information above as a practical reference for Microsoft expert discovered a series of serious code. Review each step carefully, confirm any requirements, and choose the option that best fits your situation.

FAQ

What does this guide explain about Microsoft Expert Discovered a Series of Serious Code?

It explains the main concepts, practical considerations, and useful steps related to Microsoft expert discovered a series of serious code without requiring advanced knowledge.

Who can benefit from learning about Microsoft Expert Discovered a Series of Serious Code?

This information is useful for readers who want a clear overview, practical guidance, and reliable steps related to Microsoft expert discovered a series of serious code.

What should I check before applying this information?

Review the requirements, confirm that your device, software, or situation matches the instructions, and back up important data before making major changes.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.