NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


284 Days - The Attack Window of IE in 2006

Version 6

By Marius Oiaga, Technology News Editor

6th of January 2007, 10:18 GMT

Adjust text size:


An attack window is defined as the period of time between the availability of a zero-day vulnerability and the moment the vendor produces a security update addressing the flaw. During
this time, users are exposed to exploits and have no defense barrier against attacks.

Brian Krebs over at Washington Post has compiled statistics that reveal the attack window associated with Internet Explorer 6 in the past year. Microsoft's Internet Explorer is the dominant presence on the global browser market with a share of approximately 80%, according to data made public by Market Share by Net Applications. In this context, IE users have been exposed to attacks for a total of 284 days in 2007.

"There were at least 98 days last year in which no software fixes from Microsoft were available to fix IE flaws that criminals were actively using to steal personal and financial data from users. Microsoft labels software vulnerabilities "critical" -- its most severe rating -- if the flaws could be exploited to criminal advantage without any action on the part of the user, or by merely convincing an IE user to click on a link, visit a malicious Web site, or open a specially crafted e-mail or e-mail attachment," explained Krebs.

Krebs informed that for 284 days in the past year, Proof-of-Concept and exploit code impacting either zero-day or unpatched critical vulnerabilities in Internet Explorer was available in the wild.

Although Microsoft has delivered Internet Explorer 7 on October 18, 2006, the latest Microsoft browser has not enjoyed an adoption rate that would take Internet Explorer 6 out of the equation. In fact, analytics company OneStat revealed that on November 6, 2006, the global usage share of IE7 was of just 3.06%.
Read by 1,777 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.6/5) 6 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Free IE6 VPC + Windows XP SP2 = a Microsoft Success

Internet Explorer 7 Down - Firefox 2.0 Up

PoC Published for Internet Explorer 7 Vulnerability

Firefox 2.0 Continues to Grow in the Detriment of IE7

Remove the Search Box from Internet Explorer 7

Upgrade to IE7 Optimized for Google

Internet Explorer Sinks Under 80%

God Save Internet Explorer

The First Internet Explorer 7 Vulnerability

Adobe Software and DEP Enabled in IE7

Internet Explorer 7 - Zero Vulnerabilities

$53 Million Revenue for Mozilla

The First Update for Internet Explorer 7

Seven December 2006 Security Bulletins

133 Critical and Important Microsoft Vulnerabilities

Build Your Own Customized IE7

Second Word Zero-Day Vulnerability in a Week

4 January Microsoft Security Bulletins Discontinued

Inspect OS and Software Security

The Limitations of Extended Validation SSL Certificates

ZuneMyTube

Disable Tabbed Browsing in Internet Explorer 7

The Third Exploit for Microsoft Word Vulnerability

Managing Multiple Home Tabs in IE7

The Coordinates of an MS Word Attack

Merry Vista Vulnerability!

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM