Categorized | Antivirus

2010 in Review: The Vulnerability Landscape

The number of software vulnerabilities (as measured by entries in the Common Vulnerabilities and Exposures (CVE) database) went down in 2010, although due to the complexity of modern programs they can never be completely eliminated. Criminals take advantage of this to drop their malware onto the systems of victims everywhere.

Because of this, there is a continued need for vulnerability defense solutions like Intrusion Defense Firewall (IDF), a plug-in for OfficeScan™ and Deep Security.

In recent years, both vulnerability researchers and criminals have been focusing their attacks on third-party applications. This is quite natural, as both Internet-exposed services (such as Web servers) and the OSs themselves have been made more secure. This focus on third-party applications increases the risk for typical end users, as they tend to ignore third-party programs as primary attack vectors. In addition, no common patching platform like Windows Update is provided, raising the risk of having vulnerable versions on user systems.

Let’s examine the number of publicly disclosed proof-of-concept (POC) exploits that allowed remote code execution in several applications that users commonly utilize (these are based on exploits posted on the Exploits Database site):

Application(s) Number of Exploits
Internet Explorer 7
Mozilla Firefox 3
Adobe products (Flash and Acrobat/Reader) 16
Java 4


Note the number of exploits for third-party applications above compared with browsers. Both Adobe and Java exploits are very reusable, as the vulnerable applications are present on most user systems. In addition, these can be obfuscated to bypass network-based intrusion protection systems.

Out of these critical vulnerabilities in 2010, the ones which had the most impact in the wild were:

It’s also worth noting that the DOWNAD/Conficker threat, which dates back to late 2008, was still quite active during the first half of the year. DOWNAD isn’t quite dead yet.

What kind of malware are dropped or downloaded onto user’s systems by exploits? Variants of the ZeuS family of malware were favored payloads throughout 2010. In particular, exploits using .PDF files and ActiveX controls as infection vectors were frequently used for this purpose.

These threats highlight how important it is for users to properly protect themselves against vulnerabilities by patching their software. For that, readers should consult the previous blog post “Have You Patched Your System Lately?” The CTO Insights blog also talked about it in the video “Zero Day Vulnerabilities Risk Overblown.”

Post from: TrendLabs | Malware Blog – by Trend Micro

2010 in Review: The Vulnerability Landscape

– Abhishek Bhuyan (Senior Security Researcher) on TrendLabs | Malware Blog – by Trend Micro

Related Posts
  • Grandmasters of cyber-fraud look for gains: November 2010 virus review from Doctor Web
    December 3, 2010 In November cyber-criminals demonstrated even greater creativity than before. As a result, anti-virus vendors and users were confronted with new fraud techniques involving bootkit te...
  • Rising Antivirus 2010 Review And Test
    CSA DISCLAIMER: This video taken from YouTube. As well as any other video found on this site is not hosted here, it just embedded, and it taken randomly by our system from video hosting services lik...
  • 2010 in Review: Same Old Spammers
    2010 has been an active year both for spammers and anti-spammers alike. No new spamming techniques or tricks were used in 2010. However, the spammers kept the spam threat alive and kicking by recycl...
  • 2010 in Review: 2010′s Most Dangerous List
    As 2010 comes to a close, here’s a list of the riskiest items we encountered in the past year: Hardware The riskiest hardware device used in 2010 was the German identification card reader. Th...
  • 2010 CyberCrime & Doing Time: Year In Review
    As we look back on 2010, I'd like to thank our 132,325 Visitors who read more than 214,000 stories on the blog which is a bit more than a 10% increase over our 2009 readership. I thought it might be...
  • 2010 in Review: 10 Most Remarkable Malware in 2010
    The end of 2010 is near and I thought I’d take the time out to recap how the year has been malware-wise. This is my list of the top 10 most remarkable malware families that surfaced in 2010: ...
  • 2010 in Review: No Recession for Cybercrime
    The cybercrime underground saw relatively few really revolutionary developments in 2010. However, while the rest of the world was in the economic doldrums, the cybercrime underground kept growing. R...
  • Spam and Phishing Landscape: December 2010
    The volume of spam continues to drop.  We have been monitoring the decline in overall spam volume over the last few months, and the downtrend continued in November.  The average daily volum...
  • 2010 in Review: New and Better Ways of Stealing Information
    As we mentioned earlier this week, information stealers were still the most serious threat in 2010 and will probably be so moving forward. There were three major developments in this area in 2010. Z...
  • F-Secure Internet Security 2010 TP Review
    F-Secure is one of the most used antiviruses around the world and many never even know they are using it (ISP's rebrand it). Let's see what kind of protection broadband user...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago