NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Microsoft Is Patching an Increasing Volume of Client Side Vulnerabilities

According to Symantec

By Marius Oiaga, Technology News Editor

16th of February 2007, 14:39 GMT

Adjust text size:


As a tangent to Symantec's overview of the February 2007 Microsoft Patch Tuesday, the Cupertino-based security company managed to have a look at the Redmond juggernaut's history associated
with resolving client side vulnerabilities. Client-side vulnerabilities are the software holes that require the user interaction in order for a successful exploit to be carried out. The user would have to click a link, visit a webpage, execute an email attachment in order to permit the attack.

"We all know that Microsoft has been patching more and more client-side issues lately. I had to wonder though, how may more? How rapid has this rise been, and when did it start? Luckily, I have the Symantec/SecurityFocus Vulnerability Database handy, and I decided to do some digging," explained Ben Greenbaum, Symantec Senior Security Response Researcher.

What Symantec has found is that Microsoft has been increasingly patching client side vulnerabilities since 2004. And while three years ago the Redmond Company accounted for a number of vulnerabilities smaller than 10, that number has grown constantly ever since, peaking in 2006 at over 40 client-side flaws.

This means that while in 2004, patched client-side vulnerabilities made up approximately 20% of all the issues resolved by Microsoft, at the end of 2005 their volume had more than doubled just to come to an apex of 80% in 2006.

"I should point out that the figure below illustrates patched vulnerabilities, not patches per se. If fixing one vulnerability requires four patches, one for each affected platform, then that counts as one. If one patch addresses three vulnerabilities, then that counts as three," Greenbaum explained.

Image courtesy of Ben Greenbaum.

Read by 742 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 7 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Unpatched Microsoft Vulnerabilities Have Gathered Over 1,000 Days of Exposure

Microsoft Word Strikes Again!

Internet Explorer 7 - Scarred By Vulnerabilities

It's Raining Word Vulnerabilities

Microsoft's 12 Valentine Security Patches

Microsoft's Insecure Security - the Door for New Exploits

Microsoft Confirms Word 2000 Zero-Day

A Bouquet of a Dozen Microsoft Security Bulletins, Please!

Highly Critical Microsoft Word Zero-Day

Microsoft Vulnerabilities in the Front Row at Super Bowl

Insight on the Latest Microsoft Office Zero-Day Vulnerability

Download February 2007 Microsoft Security Releases ISO Image

Microsoft Phonetically Corrects Excel Patch

Microsoft Takes Security Research out of Redmond

Microsoft Patches Critical Vulnerability In Windows Vista

Microsoft Confirms Fifth Office Zero-Day Vulnerability

Targeted Attack Scenario via a Microsoft Vulnerability

Internet Explorer 7 Blocks 1 Million Phishing Attacks Per Week

IE7 - the First Browser to Support EV SSL Certificates

Look for Vista Vulnerabilities and Thou Shall Find Them

Microsoft Revamped IE Add-ons

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM