November 29, 2007 1:40 PM PST
Study: 'Huge jump' in Microsoft flaws since last year
- Related Stories
-
Bug hunting start-up: Pay up, or feel the pain
August 3, 2007 -
Solving the Web security challenge
June 28, 2007 -
Microsoft to release four critical patches
June 7, 2007
Between 2006 and 2007, there was an almost threefold rise in Microsoft flaws, Qualys said on Wednesday.
"We have seen a huge jump in the vulnerabilities in Microsoft Office products," said Amol Sawate, manager of Qualys' vulnerability-management lab. "These charts show growth of nearly 300 percent from 2006 to 2007, primarily in new Excel vulnerabilities that can easily be exploited by getting unsuspecting users to open Excel files sent via e-mail and instant message."
Alan Paller, director of research for the Sans Institute, a computer-security training organization, said that the reason more vulnerabilities were being found was that it was becoming increasingly profitable for crooks to target the software."It isn't that Microsoft isn't doing a better job," Paller said. "The reason (is that) it is so lucrative to find vulnerabilities in Excel and Word, so there are a lot of (hackers) searching for them."
Microsoft declined to comment for this story.
Tom Espiner of ZDNet UK reported from London. CNET News.com's Ina Fried contributed to this report from San Francisco.
See more CNET content tagged:
Qualys Inc., jump, flaw, vulnerability, Microsoft Excel
64 comments
Join the conversation! Add your comment
MS continues to get abused for one reason:
It is trivial.
It is so trivial that a 12 year old kid who doesn't know what a buffer overflow is, much less how to write the simplest program can exploit MS products with ease.
MS are not so commonly and easily exploitable because it is "popular".
MS products get ripped up because MS is incompetent and doesn't want to put in the effort and money to design and write software correctly.
Note: I run version 2.0.0.10 of FireFox. Do you think each new version of FireFox is fixing security issues or do they just like releasing new numbers?
From what i understand, the MS code is quite excellent, but its burdened by huge backward compatibility legacy.
No-one else seems to be perfect...even without this legacy.
Ps anyone notcied there doesn't seem to be any statistics, or data backing this up?
It is time for the NT Phase 2 Kernel. Microsoft's biggest issue is the fact that Windows is bloated, every version of every NT release is in Vista they of course are not executable but they are there nonetheless. I believe the minwin kernel is a step in the right direction. MS needs to collaboarate first, decide what will be the easiest/most advanced architecure for future developements and technologies. Meaning what Windows architecture provides the most ease of adaptation and begin again.
If this is done Windows would be less bloated, more responsive, and of course faster. Not to mention on the cutting edge of software design. With a brand new Windows MS could absolutely blow Mac OS X out of the water.
Lean and mean is the way of the future. Small application footprints and access to massive power. People will get what they want regardless of what MS does---regardless of their monopoly or power. They should be cluing into this about now? Change will come to MS very soon if they continue on the same path.
Anyway, OneCare (just one example) SUCKS 100% and nearly killed my computer. I got rid of it an went with NOD32 and wow the old thing can run again.
I think thus shows that no one source of software can be all things to all people. Nor should they try unless they have made an assessment that the produt really offers value. I think Microsoft shot itself in the foot selling a bad product via their good name.
Microsoft"
I know perception can get skewed but it sure has felt like I've been doing a lot more Apple software patching over the past year than I have in the past.
and working like a charm. Never have any problems.
Linux even better, runs smooth.
Also, if you are running Microsoft Office on a Mac then you may have a few vulnerabilities but not nearly to the extent of Windows/Office.
curious to see the numbers of Mac flaws found this year
compared to last. I know perception can get skewed but it sure
has felt like I've been doing a lot more Apple software patching
over the past year than I have in the past." . . .
You mean you had to hit the "Software Update" button?
How many "viruses/trojans/bots/owned machines" did you have
to service?
How much security software did you have to install on all those
Macs?
How much "patching" did YOU actually do?
Bet you get paid the same as you do "supporting" Win machines
though - don't ya ;-)
Nope, it used to be good, now it's just a pay-for-training thing that doesn't actually teach anything. Don't believe me? Attend any conference and see for yourself.
But overall, it is true about flaws being found more. Apple has had a huge increase, as has Linux. Don't see a real change there.
So there name is "Without Security"
Doesn't sound like a trustworthy source to me.
Go ahead - prove to us that even 1/2 of what you're saying is even remotely true.
It just so happens that Windows is the most prevalent OS out there so why would people waste their time on a minority share when they have all of these Windows systems out there?
It has been published and predicted that Vista (sigh) will be a major target in 2008 or when the market share gets to about the 10% mark.
That is going to be a turkey shoot since it has so many new lines of code that haven't been under the microscope as much as Windows XP.
Same goes for the Mac OSX and Linux. We are already starting to see it in the Mac community where it was almost null before now a Mac needs an anti-virus solution (God forbid).
More money can be made finding flaws in MS products than any other so while the flaws continue to be found they also continue to be fixed (maybe not in a reasonable time) but fixed none the less.
I will feel better with a more mature OS such as Windowss XP on a go-forward basis than Vista because the saame people that find the flaws haven't really concentrated on Vista yet but they have had 7 years to hack at XP.
Really?
Please, name one single in-the-wild virus for OSX. Just one. I don't mean silly trojan packages which no A/V solution could hope to stop, but a real honest-to-Heaven virus.
Windows is targeted so much because it's so damned easy to target.
Lookit: If a burglar had a choice bwteen busting into:
* a fortified home owned by a passionate NRA member and his family, with someone always home, and with lots of pro-gun bumper stickers and signage about the place...
vs...
* a house three doors down with all the doors and windows unlocked, signs and bumper stickers proclaiming love for all things Mother-Earthish, nobody home half the time, and just now we see an empty HDTV carton sitting in with the trash?
Well Gee... that's a real tough choice, isn't it?
Hackers see the same choice: Either spend a lot of time, heavy risk, and more than just a little effort into breaking into those OSX or Linux boxes - or just help himself to the bazillions of soft and typically defenseless-by-design Windows targets out there, and for little to no effort.
/P
Face it - MSFT software is crap.
/P
(* ROFLOL *)
Their actions and these flaws speak louder than words!
Walt
As stated inside the article, MS does a pretty good job of keeping up with the SCUM by plugging th vulnerabilities. If people were honest and didn't try to constantly do harm to others, no form of security would ever be necessary.
OK ..... dream over ..... reboot!
Why should a bank spend money on vaults and other forms of security? After all, if someone steals all their money it isn't the banks fault.
Microsoft leaves the door open, it is their fault that Windows, Office, etc, etc, etc is so damned flawed.
It is flawed at its root, all the patches and half-assed band-aids will not solve the problem. It is impossible to make a fool proof OS. As others have shown it is possible to make an OS that unskilled children can not attack. Why can't Microsoft?
/P
If malfunctioning humans would instantly drop dead the moment they try to do harm to an OS or app, or rob a bank ..... etc.
Meanwhile, I gotta go check my firewall settings ....
Don't bother trying to make any sense of any subject because Penguinisto knows it all and will show you the error in your ways.
Thank you Penguinisto for being here to show all of us how wrong we all are.
You are my hero.