Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

May 11th, 2011, 10:13 GMT · By

Overhauled Microsoft Exploitability Index Makes Its Debut with May 2011 Patch Tuesday

SHARE:

Adjust text size:


Security
Enlarge picture
Not all Microsoft technologies should be treated equally when it comes down to assessing the exploitability risk of vulnerabilities affecting them.

This is precisely what the Redmond company focused on when introducing an overhaul to the Exploitability Index, namely a division between older product and the latest technologies available.

Announced earlier this month, the revamping is designed to illustrate the security evolution of Microsoft’s newest releases compared to their predecessors.

The software giant makes a point out of bulletproofing new products with additional security mitigations, and the evolved Exploitability Index will reflect just that.

“Microsoft is expanding its Exploitability Index to help customers on newer platforms better assess risk,” a Microsoft spokesperson told Softpedia.

“The company will continue to offer an aggregate exploitability rating for each vulnerability across all previous product versions, but will also specifically break out Exploitability Index information for Microsoft’s latest products.

“This new system demonstrates the value of the security protections and mitigations available by default for new products. Check out the MSRC blog post for more details on this change, which helps customers more easily prioritize security updates.”

The May 2011 security bulletin releases are illustrative of the changes to the Exploitability Index.

Customers can visit the Microsoft Security Bulletin Summary for May 2011 webpage in order to get an idea of how the software giant now assesses the possibility of exploits for vulnerabilities resolved on Patch Tuesday.

They will be able to see that all the vulnerabilities have two separate mentions, the Code Execution Exploitability Assessment for Latest Software Release and Code Execution Exploitability Assessment for Older Software Releases.

MS11-036 for example does not impact Office 2010, as such customers running the latest version of the productivity suite are not affected.

However, MS11-035 is used to repair vulnerabilities in Windows Server 2008 R2 SP1, a situation reflected in the Exploitability Index.

TELL US WHAT YOU THINK:

1,060 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Microsoft Patches 3 Vulnerabilities in Windows and Office (May 2011)

Fuzz Testing Essential in Bulletproofing Office 2010

Just 2 Patches Coming Up, None for Windows 7 SP1, Office 2010 or IE9

No Patches for IE9 RTW in April 2011

8 Critical Security Patches for Windows 7 SP1 Next Week, None for IE9 RTW

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM