DetailPage-MSS-KB

Microsoft small business knowledge base

Article ID: 2458544 - Last Review: August 1, 2014 - Revision: 10.0

Support for Windows Vista Service Pack 1 (SP1) ended on July 12, 2011. To continue receiving security updates for Windows Vista, make sure that you're running Windows Vista with Service Pack 2 (SP2). For more information, refer to this Microsoft webpage: Support is ending for some versions of Windows (http://windows.microsoft.com/en-us/windows/help/end-support-windows-xp-sp2-windows-vista-without-service-packs) .

On This Page

INTRODUCTION

This article describes the Enhanced Mitigation Experience Toolkit. A link is provided to download the toolkit.

More information

What is the Enhanced Mitigation Experience Toolkit?

(EMET) is a utility that helps prevent vulnerabilities in software from being successfully exploited. EMET achieves this goal by using security mitigation technologies. These technologies function as special protections and obstacles that an exploit author must defeat to exploit software vulnerabilities. These security mitigation technologies do not guarantee that vulnerabilities cannot be exploited. However, they work to make exploitation as difficult as possible to perform.

EMET also provides a configurable SSL/TLS certificate pinning feature that is called Certificate Trust. This feature is intended to detect (and stop, with EMET 5.0) man-in-the-middle attacks that are leveraging the public key infrastructure (PKI).

Are there restrictions as to the software that EMET can protect?

EMET can work together with any software, regardless of when it was written or by whom it was written. This includes software that is developed by Microsoft and software that is developed by other vendors. However, you should be aware that some software may not be compatible with EMET. For more information about compatibility, see the "Are there any risks in using EMET?" section.

What are the requirements for using EMET?

EMET requires the Microsoft .NET Framework 4.0. Additionally, for EMET to work with Internet Explorer 10 on Windows 8 and Windows Server 20121, KB2790907 (http://support.microsoft.com/kb/2790907) or a more recent version of the Compatibility Update for Windows 8 or Windows Server 2012 must be installed.

Where can I download EMET?

To download EMET, go to the related Microsoft TechNet page:
(http://www.microsoft.com/emet)

How do I use EMET to protect my software?

After you install EMET, you must configure EMET to provide protection for a piece of software. This requires you to provide the name and location of the executable file that you want to protect. To do this, use one of the following methods:
  • Work with the Application Configuration feature of the graphical application.
  • Use the command prompt utility.
To use the Certificate Trust feature, you have to provide the list of the websites that you want to protect and certificate pinning rules that apply to those websites. To do this, you have to work with the Certificate Trust Configuration feature of the graphical application. Or, you can use the new Configuration Wizard. This enables you to automatically configure EMET with the recommended settings.

Note Instructions for how to use EMET are in the user's guide that is installed together with the toolkit.

How can I deploy EMET across the enterprise?

The easiest way to deploy the current version of EMET across an enterprise is by using enterprise deployment and configuration technologies. The current versions have built-in support for Group Policy and System Center Configuration Manager. For more information about how EMET supports these technologies, please refer to the EMET user's guide.

You can also deploy EMET by using the command prompt utility. To do this, follow these steps:
  1. Install the .msi file on each destination computer. Or, put a copy of all the installed files on a network share.
  2. Run the command prompt utility on each destination computer to configure EMET.

Are there any risks in using EMET?

The security mitigation technologies that EMET uses have an application-compatibility risk. Some applications rely on exactly the behavior that the mitigations block. It is important to thoroughly test EMET on all target computers by using test scenarios before you deploy EMET in a production environment. If you encounter a problem that affects a specific mitigation, you can individually enable and disable that specific mitigation. For more information, refer to the EMET user's guide.

What is the latest version of EMET?

A new version of EMET was made available on July 31, 2014. For more information about the latest version of EMET, go to the following TechNet website:
(http://www.microsoft.com/emet)

How can I get support for EMET?

Customers who have access to Microsoft Services Premier and Professional Support, can receive fee-based advisory support through these channels. Customers who do not have Premier or Professional contracts can receive support through the following official support forum:
Enhanced Mitigation Experience Toolkit (EMET) Support (http://social.technet.microsoft.com/Forums/en/emet/threads)

Which EMET versions are currently supported? 

Every major version of EMET is supported for 24 months after its release date or for 12 months after the release date of the next major version, whichever comes first. The following table displays the lifecycle of all EMET versions.
Collapse this tableExpand this table
EMET versionLifecycle start dateSupport end dateNotes
EMET 2.x and earlierSee notesEMET 2.x and earlier versions are not officially supported.
EMET 3.xMay 15, 2012May 13, 2014
EMET 4.xJune 17, 2013June 9, 2015
EMET 5.xJuly 31, 2014July 12, 2016Support ends 24 months after release or 12 months after the next major version (EMET 6.x) is released, whichever comes first.

Applies to
  • Windows 8
  • Windows 8 Enterprise
  • Windows 8 Pro
  • Windows Server 2012 Datacenter
  • Windows Server 2012 Essentials
  • Windows Server 2012 Foundation
  • Windows Server 2012 Standard
  • Windows 7 Service Pack 1, when used with:
    • Windows 7 Enterprise
    • Windows 7 Professional
    • Windows 7 Ultimate
    • Windows 7 Home Premium
    • Windows 7 Home Basic
  • Windows Server 2008 R2 Service Pack 1, when used with:
    • Windows Server 2008 R2 Standard
    • Windows Server 2008 R2 Enterprise
    • Windows Server 2008 R2 Datacenter
  • Windows Server 2008 Service Pack 2, when used with:
    • Windows Server 2008 for Itanium-Based Systems
    • Windows Server 2008 Datacenter
    • Windows Server 2008 Enterprise
    • Windows Server 2008 Standard
    • Windows Web Server 2008
  • Windows Vista Service Pack 2, when used with:
    • Windows Vista Business
    • Windows Vista Enterprise
    • Windows Vista Home Basic
    • Windows Vista Home Premium
    • Windows Vista Starter
    • Windows Vista Ultimate
    • Windows Vista Enterprise 64-bit Edition
    • Windows Vista Home Basic 64-bit Edition
    • Windows Vista Home Premium 64-bit Edition
    • Windows Vista Ultimate 64-bit Edition
    • Windows Vista Business 64-bit Edition
  • Microsoft Windows Server 2003 Service Pack 2, when used with:
    • Microsoft Windows Server 2003, Standard Edition (32-bit x86)
    • Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Web Edition
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003, Enterprise x64 Edition
    • Microsoft Windows Server 2003, Standard x64 Edition
    • Microsoft Windows XP Professional x64 Edition
    • Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
    • Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
  • Microsoft Windows XP Service Pack 3, when used with:
    • Microsoft Windows XP Home Edition
    • Microsoft Windows XP Professional
Keywords: 
atdownload kbexpertiseinter kbsecurity KB2458544
Share
Additional support options
Ask The Microsoft Small Business Support Community
Contact Microsoft Small Business Support
Find Microsoft Small Business Support Certified Partner
Find a Microsoft Store For In-Person Small Business Support