Microsoft Corp. was forced to pick up the patching pace in the second half of 2008, the company admitted Wednesday, as it fixed 67% more flaws and released 17% more security updates in the period than it had in the first six months of the year.
Included in the bugs patched during the latter months of the year was the vulnerability exploited by Conficker, a worm that led to the biggest infection outbreak in years and a minor media frenzy last week.
Microsoft patched 97 different vulnerabilities in 42 separate security update in the second half of 2008, compared to 58 vulnerabilities in 36 updates in the first half.
Vinnie Gullotto, the general manager of the Microsoft Malware Protection Center, acknowledged the increase. "The number [of patched vulnerabilities] did go up, but a lot has to do with our methodology."
Microsoft's Security Intelligence Report explained it differently. "Although the total number of security bulletins in [the second half of 2008] was on par with the last several periods, there was a significant increase in the number of CVE identifiers addressed per security bulletin in [the second half of 2008]," the report stated. The average number of Common Vulnerability and Exposure (CVE) identifiers rose from an average of 1.6 per security bulletin in the first half of 2008 to 2.3 in the final six months.
In plain English, that means Microsoft packed more individual patches into the average security update.
During the second half of 2008, Microsoft issued several multi-patch updates, including MS08-052, a five-patch update for the GDI+ component of Windows; MS08-058, a six-patch update for Internet Explorer (IE); MS08-072, an eight-patch fix for Microsoft Word; and MS08-073, a four-patch update for IE.
Gullotto also argued that the number of bugs Microsoft quashed was less important than the number of exploits actually crafted for, and released into the wild against, those vulnerabilities.
"The number of exploits against those [bugs] stayed about the same as in the first half of the year," he said. The report did not include a complete tally of all exploits aimed at Microsoft software during the last six months of the year, though it included some data related to browser and document file format bugs.
Conficker, the most prolific worm in several years got its start last year when it began to exploit unpatched Windows machines just weeks after Microsoft issued one of its two emergency updates for the period. "Fortunately, Conficker was a rarity," said Gullotto, referring to the scarcity of worms that attack the operating system and self-propagate quickly through networks.
The other "out-of-band" update was released in mid-December to plug a critical hole in IE which had already been exploited by criminals.
Even as Gullotto admitted that Microsoft had to patch more bugs as 2008 proceeded, he defended the company's track record. "We're clearly seeing the results of the progress we've made in software development," he said, pointing out that the company's newer software is more secure than older code. According to data gathered from the Malicious Software Removal Tool (MSRT), the anti-malware utility Microsoft updates and redistributes each month to Windows machines, the real-world infection rate of PCs running Windows Vista Service Pack 1 (SP1) is 61% less than that of systems powered by Windows XP SP3.
"Older versions typically do have more vulnerabilities, that's true," he said, "but one of the good things is that we're being transparent about it, we're telling people about the vulnerabilities."
Micrsosoft's new security report, labeled as "Volume 6," is available for download as a PDF file from the company's Web site.
References
- FAQ: Conficker clock ticks toward April 1 deadline
- Microsoft patches 8 critical bugs in Windows, Office
- Microsoft issues mammoth security update, biggest in five years
- 'Amazing' worm attack infects 9 million PCs
- Microsoft patches critical IE bug with emergency update
- Microsoft Malware Protection Center - Security Intelligence Report
Latest on Intrusion Detection & Prevention
- Cyberoam CR50ia UTM appliance
- Great firewall of News Limited saves $5.5M a year
- Estonia readies for the next cyberattack
- 3Com to blend security brains, enterprise brawn
- SQL injection attacks led to massive data breaches
- Attacks on US, Korea Web sites leave a winding trail
- Twitter taken down by denial-of-service attack
- The botnet world is booming
- Two years on, Estonia hardens its electronic defenses
- DNS attack downs Internet in parts of China
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
- SOE Architect - Permanent - North Ryde - $9/09/2010
Other
I.T. & T
SOE Architect - Permanent - North Ryde - $ - Business Analyst- Super/insurance experience- Mailroom integration!9/09/2010
Other
I.T. & T
Business Analyst- Super/insurance experience- Mailroom integration! - SOE Apple systems engineer - Attractive Package - North Ryde Location9/09/2010
Other
I.T. & T
SOE Apple systems engineer - Attractive Package - North Ryde Location - Senior Analyst/Programmer (Natural Adabas)9/09/2010
Other
I.T. & T
Senior Analyst/Programmer (Natural Adabas) - JDE Technical Systems Analyst/Consultant - Fixed term contract or Perm9/09/2010
Other
I.T. & T
JDE Technical Systems Analyst/Consultant - Fixed term contract or Perm - Client Coordinator - SAP R3 Production Experience Required - Leading I9/09/2010
Other
I.T. & T
Client Coordinator - SAP R3 Production Experience Required - Leading I - Service Desk Analyst9/09/2010
Other
I.T. & T
Service Desk Analyst
TechWorld Blogs
Recent blog posts
- Data trumps speed in broadband battleground
- Windows Phone 7: how big can it get?
- NBN gets a turn at political football
- Internet filter gets caught up in politics
- TechWorld Forums goes live
- Selective sourcing the hybrid of cloud services
- Social networks catch more business attention
- RIP Kin
- Telstra’s copper and NBN’s fibre: will the two ends meet?
- RIP Windows 2000, XP lives on
Recent comments
- How do you remove it
11 hours 58 min ago - Can't compose, forward or reply to emails with new yahoo mail fo
21 hours 10 min ago - Awesome
1 day 52 min ago - This is great news, AMD just
1 day 4 hours ago - Same kind of call...
2 days 12 hours ago - windows scam
2 days 12 hours ago - Ease..
2 days 20 hours ago - Bandwidth vs Speed . . . . . . They are the same thing
2 days 20 hours ago - I have plenty of referrals left
2 days 22 hours ago - Plagiarism
3 days 18 hours ago - Event veiw scam
4 days 59 min ago - how wide a range does this system tracks.
4 days 9 hours ago - Quality of journalism
4 days 11 hours ago - Nice post on SEO. SEO helps
4 days 15 hours ago - They got the business from me!
5 days 8 hours ago - can' wait to see!!!
5 days 12 hours ago - ubuntu 10.10 beta
5 days 13 hours ago - Download Academy
5 days 14 hours ago - Scam from India
5 days 18 hours ago - they TRIED to get me
5 days 21 hours ago










Comments
Post new comment