PC users using obsolete software despite vulnerabilities: Kaspersky

Security

by CBR Staff Writer| 04 February 2013

Adobe Shockwave and Flash, Apple iTunes/QuickTime, and Java have the highest number of vulnerabilities

According to a report by Kaspersky Lab, a significant number of PC users are using old - or even obsolete - versions of popular software despite vulnerabilities.

According to the report, over 132 million vulnerabilities have been discovered in various programmes, which accounts an average of 12 vulnerabilities per user among more than 11 million users.

Among the popular software programmes, Adobe Shockwave and Flash, Apple iTunes/QuickTime, and Java have highest number of vulnerabilities.

Despite vulnerabilities, the users of older and particularly dangerous editions of Oracle Java, Adobe Flash Player and Adobe Reader are highly reluctant to upgrade to newer and safer versions, the research revealed.

The security firm found that over 800 different vulnerabilities were discovered during last year of which, 37 were found on at least 10% of computers during one week in 2012.

Out of the 37 vulnerabilities only eight vulnerabilities are found in the widespread exploit packs used by cybercriminals which include five vulnerabilities in Oracle Java, two vulnerabilities in Adobe Flash Player and one vulnerability found in Adobe Reader.

Kaspersky Lab analysts said that the vulnerabilities account for 70% of all detected software flaws.

Kaspersky Lab vulnerability research expert Vyacheslav Zakorzhevsky said that a fix for a security loophole shortly after discovery is not enough to make users and businesses secure.

"Inefficient update mechanisms have left millions of users of Java, Adobe Flash and Adobe Reader at risk," Zakorzhevsky said.

"This, along with the whole series of critical vulnerabilities found in Java in 2012 and early 2013, highlights the need for the most up-to-date protection methods."

"Companies should take this problem very seriously, as security flaws in popular software have become the principle gateways for a successful targeted attack."

Despite the availability of a new version of Java, only 28.2% of users have upgraded to the safer version while over 70% are using the old programmes leaving their system vulnerable to Java exploits, the research added.

A 2010 version of Adobe Flash Player which is obsolete now is being used on an average of 10.2% computers while a vulnerable Adobe Reader version is still being used by 13.5% of users.

Comments
Post a comment

Comments may be moderated for spam, obscenities or defamation.

Join our network

732 people like this.
0 people follow this.

Security Intelligence

Privcy Policy

We have updated our privacy policy. In the latest update it explains what cookies are and how we use them on our site. To learn more about cookies and their benefits, please view our privacy policy. Please be aware that parts of this site will not function correctly if you disable cookies. By continuing to use this site, you consent to our use of cookies in accordance with our privacy policy unless you have disabled them.