Threats in Plain Sight: Bit9 Identifies 'The Dirty Dozen' - 2008's Most Popular Applications with Critical Security Vulnerabilities
Posted on: Thursday, 11 December 2008, 09:15 CST
Reputable programs found vulnerable; Security gaps often left unaddressed
(Logo: http://www.newscom.com/cgi-bin/prnh/20080204/BIT9LOGO )
The list this year expanded to include 12 applications, up from 10 last year, due to the increase in vulnerabilities and the popularity of applications such as Skype and Yahoo! Assistant that are often used by employees within an enterprise.
Five of the top 12 applications with known vulnerabilities include:
- Mozilla Firefox, versions 2.x and 3.x
- Adobe Acrobat, versions 8.1.2 and 8.1.1
- Microsoft Windows Live (MSN) Messenger, versions 4.7 and 5.1
- Apple iTunes, versions 3.2 and 3.1.2
- Skype, version 3.5.0.248
Each application on the list has the following characteristics:
- Runs on Microsoft Windows.
- Is well-known in the consumer space and frequently downloaded by individuals.
- Is not classified as malicious by enterprise IT organizations or security vendors.
- Contains at least one critical vulnerability that was:
- first reported in
January 2008 or after, - registered in the U.S. National Institute of Standards and Technology's (NIST) official vulnerability database at http://nvd.nist.gov, and given a severity rating of high (between 7.0-10.0) on the Common Vulnerability Scoring System (CVSS).
- first reported in
- Relies on the end user, rather than a central IT administrator, to manually patch or upgrade the software to eliminate the vulnerability, if such a patch exists.
- The application cannot be automatically and centrally updated via Enterprise tools such as Microsoft SMS & WSUS.
"Year after year, we see a growing number of applications within the enterprise creating security vulnerabilities that are easily prevented through better visibility across endpoints, and a more centralized patch-management process," said
To read the full list of applications, which includes products from Symantec, Yahoo!, Trend Micro, Sun Microsystems and more, visit here to download the research note. With this note, IT managers can learn more about the application vulnerabilities, along with the benefits of using application whitelisting, a proactive approach to endpoint security.
About Bit9, Inc.
Bit9 is the pioneer and leader in enterprise application whitelisting. The company's patented application control solutions ensure only trusted and authorized applications are allowed to run, eliminating the risk
caused by malicious, illegal and unauthorized software. Unlike traditional, reactive controls that try to scan and prevent the never-ending list of unauthorized software, Bit9 leverages the Bit9 Global Software Registry(TM) -- the world's largest database of software intelligence - to ensure only authorized applications can run, delivering the highest levels of desktop security, compliance, and manageability. Bit9 customers include companies in a wide variety of industries, such as retail, financial services, healthcare, e-commerce, telecommunications, as well as government agencies. Founded in 2002, Bit9 is privately held and based in
Press Contacts:
Text 100 for Bit9, Inc.
617-399-4909
SOURCE Bit9, Inc.
Source: PR Newswire
Related Articles
- Security Vulnerability Assessment Tool for Universities and Educational Institutions From TEEX
- Fortify Software to Collaborate With HP on Application Lifecycle Security Solutions to Reduce Business Risk
- TEEX Security Vulnerability (SAST) Demo on YouTube
- Dimension Data Study Shows 73% of Networking Devices are Running with Known Security Vulnerabilities
- AlertSite(R) Clicks to TransMedia Group to Publicize Its Worldwide Web Performance Monitoring and Security Vulnerability Scanning Services
- Lucent Technologies and Endforce, Inc., Join Forces to Improve and Centralize Enterprise Network Access Security; ENDFORCE Enterprise Software With Lucent VitalQIP Software Isolates Problem Computers From Corporate Network Resources
- NEON Enterprise Software, Inc. Eases Migration to IBM(R) DB2 Version 8 for Z/OS
- Y3K Secure Enterprise Software Reports Pacific Communication Systems Acquisition Terms
- Y3K Secure Enterprise Software Reports Financial Results
User Comments (0)

RSS Feeds