Feeds

Who's riddling Windows PCs with gaping holes? It's your crApps

New study: Microsoft slashes bugs, Java and Adobe bring up the rear

High performance access to file storage

Nearly nine out of ten security vulnerabilities in Windows computers last year were the fault of popular third-party applications, as opposed to Microsoft's own software.

That's according to security biz Secunia, which analysed flaws found in the most-used 50 Windows programs - 29 from Microsoft (including its operating system family) and 21 from third-party developers.

In 2012, 86 per cent of 2,755 vulnerabilities identified by Secunia's study were found in code developed outside of Microsoft; that's up 8 percentage points on 2011's 78 per cent, we're told. In 2007, the figure was just 57 per cent.

Secunia credited Microsoft for its continued focus on shoring up security measures in its products, and reducing its share of the software vulnerabilities on its Windows platform. The Danish biz added that sysadmins must not forget to roll out updates for all installed code rather than just Microsoft's and the few "usual suspects from other vendors".

Last year, according to Secunia, 5.5 per cent of the vulnerabilities found were present in Windows XP, Vista and Windows 7 operating systems and 8.5 per cent were in Microsoft's user-land programs. In 2011, the numbers were 78 per cent in non-Microsoft code, 10 per cent in Windows OSes and 12 per cent in Microsoft applications.

The number of vulnerabilities tracked by Secunia continues to increase, almost doubling over the last five years. Adobe Flash Player, Adobe Reader and Oracle's Java runtime engine are among the third-party applications included in Secunia's study.

“Companies cannot continue to ignore or underestimate non-Microsoft programs as the major source of vulnerabilities that threaten their IT infrastructure and overall IT-security level. The number of vulnerabilities is on the increase, but many organisations continue to turn a blind eye, thereby jeopardising their entire IT infrastructure: It only takes one vulnerability to expose a company,” said Morten R. Stengaard, Secunia’s director of product management.

The total number of vulnerabilities in the top-50 most popular Windows programs was 1,137 in 2012. Most of these were rated by Secunia as either highly critical (78.8 per cent) or extremely critical (5.3 per cent). Despite the hype about zero-day exploits, 84 per cent of vulnerabilities had a patch available on the day they were disclosed, up from 72 per cent in 2011.

More details on all these figures and more than be found in Secunia's Vulnerability Review 2013 report. The biz collected the figures from anonymised data gathered from system scans by the millions of users of Secunia's patch management software, Personal Software Inspector. ®

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
Experian subsidiary faces MEGA-PROBE for 'selling consumer data to fraudster'
US attorneys general roll up sleeves, snap on gloves
Oz bank in comedy Heartbleed blog FAIL
Bank: 'We are now safely patched.' Customers: 'You were using OpenSSL?'
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.