Skip to content

Enable CFG in node.exe #42100

Description

@msidhartha7

BinSkim is a binary static analysis tool that provides security and correctness results for Windows Portable Executable and *nix ELF binary formats.

  • Browser : N/A
  • OS: Windows 8

error BA2008: 'node.exe' does not enable the control flow guard (CFG) mitigation. To resolve this issue, pass /guard:cf on both the compiler and linker command lines. Binaries also require the /DYNAMICBASE linker option in order to enable CFG.

Screenshot 2022-02-23 at 6 17 17 PM

Package used : https://github.com/microsoft/binskim
Command used : .\BinSkim.exe analyze < path to executable >

Activity

  1. nschonni commented on Feb 23, 2022

    @nschonni
  2. transferred this issue fromnodejs/nodejs.orgon Feb 23, 2022
  3. changed the title [-]BinSkim Security Analysis[/-] [+]Enable CFG in node.exe[/+] on Feb 23, 2022
  4. added
    buildIssues and PRs related to Node.js builds or CI infrastructure.
    windowsIssues and PRs related to the Windows platform.
    on Feb 23, 2022
  5. richardlau commented on Feb 23, 2022

    @richardlau
    Member

    cc @nodejs/platform-windows

  6. msidhartha7 commented on Feb 24, 2022

    @msidhartha7
    Author

    Please check for Linux and MacOS binaries also.

  7. Trott commented on Feb 24, 2022

    @Trott
    Member

    Please check for Linux and MacOS binaries also.

    Control flow guard isn't a thing that exists on those platforms.

  8. msidhartha7 commented on Feb 24, 2022

    @msidhartha7
    Author

    I meant to say, run the Mac and Linux binaries against BinSkim to generate their reports.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    buildIssues and PRs related to Node.js builds or CI infrastructure.windowsIssues and PRs related to the Windows platform.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions