Bekker's Blog

Blog archive

Which Unpatched Holes Most Appeal to Attackers?

There are few better ways to guarantee a system will be breached, compromised and exploited than failing to keep up with vendors' patches. Yet millions of public-facing systems run unpatched.

In an effort to document which previously reported security vulnerabilities are most popular with attackers, government public computer security awareness agencies from five countries on Wednesday released a Top 30 list of targeted high-risk vulnerabilities.

"This Alert provides information on the 30 most commonly exploited vulnerabilities used in these attacks, along with prevention and mitigation recommendations," read an alert from the U.S. Department of Homeland Security's National Cybersecurity and Communications Integration Center and the U.S. Computer Emergency Readiness Team.

An analysis by the Canadian Cyber Incident Response Centre provides the foundation for the list, which was jointly developed by government computer security organizations in Australia, Canada, New Zealand, the United Kingdom and the United States.

The vulnerabilities are not listed by severity. Instead, they are grouped by the vendor or project whose software is affected. Microsoft accounts for 16 of the vulnerabilities, Adobe for 11, Oracle for 2 and OpenSSL for 1.

What's both interesting and depressing about the list is how old some of the vulnerabilities are. For example, in the Microsoft list, some of the 30 most commonly exploited vulnerabilities date to 2009 and 2008, as well as an Internet Explorer malware issue, which first emerged almost nine years ago.

On Microsoft platforms, the attackers' favorite flaws come from the following bulletins:

  • MS08-042
  • MS09-067
  • MS09-072
  • MS10-018
  • MS10-087
  • MS11-021
  • MS12-027
  • MS12-060
  • MS13-008
  • MS13-022
  • MS13-038
  • MS14-012
  • MS14-017
  • MS14-021
  • MS14-060

The malware issue with Internet Explorer is CVE-2006-3227.

The U.S. version of the Top 30 bulletin is available here.

Posted by Scott Bekker on April 29, 2015


Featured

  • Microsoft Appoints Althoff as New CEO for Commercial Business

    Microsoft CEO and chairman Satya Nadella on Wednesday announced the promotion of Judson Althoff to CEO of the company's commercial business, presenting the move as a response to the dramatic industrywide shifts caused by AI.

  • Broadcom Revamps VMware Partner Program Again

    Broadcom recently announced a significant update regarding its VMware Cloud Service Provider (VCSP) program, coinciding with the release of VMware Cloud Foundation (VCF) 9.0, a key component in Broadcom’s private cloud strategy.

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.