Patch/Configuration Management, Vulnerability Management

Secunia: Nearly one in three corporate applications missing critical patches

Nearly a third of all applications on corporate networks are missing critical security patches and are at risk to security breaches, according to a new report from Secunia.

The Danish provider of vulnerability assessment software pointed the finger at weaknesses in commercial vulnerability-scanning tools as the culprit.

Those products focus on vulnerabilities in network services, weak passwords and open shares in only the 20 to 50 most used applications deployed in corporate environments, the report said.

The typical network environment contains a wide range of applications, including home-grown ones, not covered by the commercial products that are left open to vulnerabilities, the report said.

Beta tests of Secunia's new Network Software Inspector by 1,600 IT administrators indicated that 28 percent of the applications on the corporate systems scanned during the beta program were vulnerable to exploits. Secunia has said its new product can detect potential security problems — most notably, critical security patches — in more than 4,000 applications.

Microsoft products in corporate environments "appear to be updated fairly regularly," due mostly to widespread awareness of the monthly Patch Tuesday round of security fixes from Microsoft, Secunia reported.

The picture is even more grim at the end-user desktop, the report said. In the five months since its free online Secunia Software Inspector desktop application scanning tool has been available, the company found that 1.4 million of the 4.9 million applications on end-user PCs scanned were missing critical security patches from vendors.

An official from the security vendor could not be reached for comment today.

Among the major offending applications: 33 percent of all QuickTime 7 and 27 percent of all Winamp 5 installations are missing important security updates and are vulnerable to exploits, the report said.

On the positive side, Secunia reported that users of the Firefox and Opera browsers remember to keep their software updated more than Internet Explorer users. Only five percent of Firefox 2 and 13 percent of Opera 9.x installations miss security updates; the corresponding numbers for Internet Explorer 6/7 are 10 percent and five percent, respectively.

Jakob Balle, Secunia IT development manager, said on the Secunia Security Watchdog Blog on Wednesday that most end-users seem unaware of the dangers or unwilling to find the time to fix flaws.

"While most people are aware of the need to update their anti-virus patterns and to raise their firewall shields, it appears that too many users either don’t know that their systems are vulnerable to significant issues or that they simply don’t want to spend the necessary time scouring for vulnerability information and the relevant vendor patches to properly address the issues," he said.



Get more IT security news. Click here for SC Magazine Blogs.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.