Worry about browsers not OS, says Microsoft

Vista more secure, XP still an issue.

The era of operating system vulnerability is slowly drawing to a close, with more than nine out of ten published software vulnerabilities now appearing in applications, Microsoft's latest half-yearly report has suggested.

According to the company's Security Intelligence Report for the first half of 2008, OS vulnerabilities are now stable at between 6 and 8 percent of those reported, a level they have been at since the first half of 2006. Vulnerabilities in Windows XP and Vista have shown a modest decrease in 2008, continuing a similar trend over the same period.

But the report paints a more complex picture in terms of which platforms are the ones most likely to run vulnerable applications. Vista scores well, with Microsoft-based software accounting for only 6 percent of vulnerabilities on that platform, with none of the top ten browser-based holes hitting the OS.

Over the period, the biggest Vista-based software vulnerabilities appeared to be in two ActiveX controls installed only in China, which would seem to confirm the relative obscurity of serious issues on the platform.

XP, by contrast, is still Microsoft's biggest headache, with 42 percent of all app holes on that platform coming from Microsoft's own software.

Using the number of PC's cleaned per 1,000 executions of Microsoft's own Malicious Software Removal Tools (MSRT), Visa SP1 scored 4.5, while the different updates of XP scored between 9.2 and 33.8. All of this confirms what has been well established in the past - XP and its applications are still relatively vulnerable, while the newer Vista and its applications do considerably better.

Across the industry as a whole, software vulnerabilities classified by the industry standard Common Vulnerability Scoring System v2 (CVSSv2) as ‘severe' now account for 7.3 percent of those made public, with a startling 41 percent classified as ‘high'. More encouragingly, Microsoft reports, only 10.4 percent of holes had publically-available exploit code.

In truth, it is extremely hard to gauge from the report how Windows is stacking up against rival platforms such as Apple or Linux in terms of OS and app holes, but the overall message to take away appears to be that the OS is not the main worry. The big concern now is browsers on all platforms, including Windows.

Analysing these by locale showed that China was the most likely place for browser-based exploits to hit, with 46.6 percent of them happening in that country across all platforms. The US came second on 23 percent, Russia third with 7 percent and the UK some way back with 2.4 percent.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

The Open Sourcerer | Published: 07:27 GMT, 04 November 2008

"In truth, it is extremely hard to gauge from the report how Windows is stacking up against rival platforms such as Apple or Linux in terms of OS and app holes, but the overall message to take away appears to be that the OS is not the main worry." Huh? Where does it say that you are going to get infexted by running Firefox, Thunderbird or OpenOffice.org on Linux or MAC? All the apps are Microsoft and all the issues are with Microsoft OSs. Bizarre. Take a look at the wildlist.org. It will show all of the virus currently active. Try and find more than 1 or two not specifically targeting M$ APIs.

Related Security news

Antivirus programs fail to stop new malware

One in three systems infected.

Adobe sorry for 16-month-old Flash bug

Unpatched vulnerability 'slipped through the cracks'

HTML 5 leaves client storage open to web attacks

Security researcher says web apps could be vulnerable

Rugged Manifesto calls on developers for secure code

Security professionals call for better programming practices



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Challenges and opportunities of PCI

The Payment Card Industry Data Security Standard provides an enterprise structure for improving operational, security, and audit performance. The benefits of the PCI DSS go beyond audit costs and results.

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *