Government Technology

The Dirty Dozen -- 2008's Most Popular Applications with Critical Security Vulnerabilities



December 17, 2008 By

Bit9 unveiled its annual ranking of popular consumer applications with known security vulnerabilities. Often running outside of the IT department's knowledge or control, these applications can be difficult to detect; they create data leakage risk in endpoints that are otherwise secure; and cause compliance breaches that can result in costly fines. The list, published in a research brief entitled "2008's Popular Applications with Critical Vulnerabilities," is designed to highlight the need for greater visibility and control over organizations' endpoints, including laptops, PCs, servers and Point-of-Sale systems.

The list this year expanded to include 12 applications, up from 10 last year, due to the increase in vulnerabilities and the popularity of applications such as Skype and Yahoo! Assistant that are often used by employees within an enterprise.

Five of the top 12 applications with known vulnerabilities include:

  • Mozilla Firefox, versions 2.x and 3.x
  • Adobe Acrobat, versions 8.1.2 and 8.1.1
  • Microsoft Windows Live (MSN) Messenger, versions 4.7 and 5.1
  • Apple iTunes, versions 3.2 and 3.1.2
  • Skype, version 3.5.0.248

Each application on the list has the following characteristics:

  • Runs on Microsoft Windows.
  • Is well-known in the consumer space and frequently downloaded by individuals.
  • Is not classified as malicious by enterprise IT organizations or security vendors.
  • Contains at least one critical vulnerability that was first reported in January 2008 or after and is registered in the U.S. National Institute of Standards and Technology's (NIST) official vulnerability database and given a severity rating of high (between 7.0-10.0) on the Common Vulnerability Scoring System (CVSS).
  • Relies on the end user, rather than a central IT administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists.
  • The application cannot be automatically and centrally updated via Enterprise tools such as Microsoft SMS & WSUS.

"Year after year, we see a growing number of applications within the enterprise creating security vulnerabilities that are easily prevented through better visibility across endpoints, and a more centralized patch-management process," said Harry Sverdlove, CTO, Bit9. "2008 has been no exception. This year, along with the widely reported huge increase in malware, the number of well-known applications causing security problems for companies has also increased. Our annual ranking now covers 12 applications, up from 10 last year.


You may use or reference this story with attribution and a link to
http://www.govtech.com/security/The-Dirty-Dozen----2008s-Most.html


| More

Comments

DNukem    |    Commented December 18, 2008

I think the World Bank, the IMF, the Pentagon and CitiBank would want Windows on that list as the most vulnerable. After all the World Bank packed up their servers and sent them to MS to figure out. CitiBank had all 40 WIndows servers hacked including their password server....and the IMF lost critical banking information.

DNukem    |    Commented December 18, 2008

I think the World Bank, the IMF, the Pentagon and CitiBank would want Windows on that list as the most vulnerable. After all the World Bank packed up their servers and sent them to MS to figure out. CitiBank had all 40 WIndows servers hacked including their password server....and the IMF lost critical banking information.

DNukem    |    Commented December 18, 2008

I think the World Bank, the IMF, the Pentagon and CitiBank would want Windows on that list as the most vulnerable. After all the World Bank packed up their servers and sent them to MS to figure out. CitiBank had all 40 WIndows servers hacked including their password server....and the IMF lost critical banking information.

Anonymous    |    Commented December 22, 2008

Mozilla Firefox Adobe Flash & Acrobat Sun Java Runtime Environment (JRE) Apple QuickTime, Safari & iTunes Symantec Norton Trend Micro Office Scan Citrix Products Aurigma, Lycos Skype Yahoo! Assistant Microsoft Windows Live (MSN) Messenger

Anonymous    |    Commented December 22, 2008

Mozilla Firefox Adobe Flash & Acrobat Sun Java Runtime Environment (JRE) Apple QuickTime, Safari & iTunes Symantec Norton Trend Micro Office Scan Citrix Products Aurigma, Lycos Skype Yahoo! Assistant Microsoft Windows Live (MSN) Messenger

Anonymous    |    Commented December 22, 2008

Mozilla Firefox Adobe Flash & Acrobat Sun Java Runtime Environment (JRE) Apple QuickTime, Safari & iTunes Symantec Norton Trend Micro Office Scan Citrix Products Aurigma, Lycos Skype Yahoo! Assistant Microsoft Windows Live (MSN) Messenger


Add Your Comment

You are solely responsible for the content of your comments. We reserve the right to remove comments that are considered profane, vulgar, obscene, factually inaccurate, off-topic, or considered a personal attack.

Collaboration for the Public Sector



Collaborative Justice: Transforming Criminal Justice Services Through Unified Collaboration
This issue brief examines video collaboration in every stage of the human justice process, demonstrating how this technology can not only make services more efficient, affordable, and accessible.

Cloud-Based Services Accelerate Public Sector Adoption of Video Collaboration
Today, thanks to new cloud technologies and high-quality networks, mobile video services - which provide not only cost savings but which help governmental interactions become more efficient - are more feasible than ever before.

Modernization as a Service: Acquiring IT through Innovative Procurement

Five Ways Collaboration is Driving Government Performance

Mobile Video Collaboration: The New Business Reality