EP_X0FF wrote:How do you want to prevent/block if you don't know what is it, how does it work and what it exploits? By denying everything? Becoming a slave of "security" trashware is not the option for everyone.
Many zero-day exploits can be easily mitigated by utilising a variety of programs, some of them free. And you don't need to become a slave at all. For example, if this wasn't a kernel-level exploit, opening the document in Sandboxie would probably prevent the exploit.
I've been told that kernel-level exploits can pretty much do what they like, no matter what security is in place. However, I just wanted to check, and since there appears to be a nice description of how exactly this particular kernel zero-day exploit works, I thought someone could share some insight into possible methods to block it. If it's not possible, then that answers the question too.