{"id":1073,"date":"2015-01-12T11:14:31","date_gmt":"2015-01-12T11:14:31","guid":{"rendered":"http:\/\/www.intelligentcio.com\/?p=1073"},"modified":"2015-01-12T11:14:31","modified_gmt":"2015-01-12T11:14:31","slug":"internet-explorer-most-vulnerable-microsoft-windows-component","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2015\/01\/12\/internet-explorer-most-vulnerable-microsoft-windows-component\/","title":{"rendered":"Internet Explorer &#8216;most vulnerable&#8217; Microsoft Windows component"},"content":{"rendered":"<p>Internet Explorer, Microsoft\u2019s ubiquitous web browser that remains one of the most used internet browsing applications worldwide, has topped a list of the most frequently targeted Windows components. Prepared by ESET, the report titled &#8216;<a href=\"http:\/\/media.ne.cision.com\/l\/lhcemhho\/www.welivesecurity.com\/wp-content\/uploads\/2015\/01\/Windows-Exploitation-in-2014.pdf\"><span class=\"s1\">Windows exploitation in 2014<\/span><\/a>&#8216; also found that usage of Windows XP, the popular Operating System (OS) that is no longer supported by Microsoft, remains high and users of this OS are at greater risk due to the lack of Microsoft&#8217;s latest anti-exploit security features.<\/p>\n<p class=\"p2\">Compared to the results from <a href=\"http:\/\/media.ne.cision.com\/l\/lhcemhho\/www.welivesecurity.com\/2013\/12\/13\/exploit-protection-for-microsoft-windows\/\"><span class=\"s1\">last year<\/span><\/a>, the number of exploit attacks on Microsoft components grew in 2014. \u201dThis year was especially hard on users of the Internet Explorer browser, as Microsoft addressed twice as many vulnerabilities as in 2013,\u201c explains Mohamed Djenane, Security Specialist, ESET Middle East. \u201cMicrosoft was highly active and quick to address a large number of these vulnerability in the same year itself, thus reducing the risk for users.\u201d<\/p>\n<p class=\"p2\">The most notorious example of an Internet Explorer vulnerability being exploited in the wild was <a href=\"http:\/\/media.ne.cision.com\/l\/lhcemhho\/www.welivesecurity.com\/2014\/11\/20\/first-exploitation-of-unicorn-bug\/\"><span class=\"s1\">the Unicorn bug<\/span><\/a>. This vulnerability could be used by an attacker to run arbitrary code on a remote machine while bypassing the Enhanced Protected Mode (EPM) sandbox in Internet Explorer 11 as well as Microsoft\u2019s free anti-exploitation tool, the Enhanced Mitigation Experience Toolkit (EMET). In the report, ESET researchers also offer their findings on the <a href=\"http:\/\/media.ne.cision.com\/l\/lhcemhho\/www.welivesecurity.com\/2014\/09\/22\/back-in-blackenergy-2014\/\"><span class=\"s1\">BlackEnergy<\/span><\/a> trojan, which exploits a bug in Microsoft PowerPoint.<\/p>\n<p class=\"p2\">The report offers information about not just the main types of vulnerabilities present in Microsoft Windows over the past year, but also highlights the mitigation techniques that Microsoft introduced with the latest versions of its operating system. \u201cUnfortunately, many users still use Windows XP without any anti-exploit security features, and these users are therefore constantly exposing themselves to significant risk of being infected,\u201d Mohamed Djenane adds.<\/p>\n<p class=\"p2\">Djanane believes there is good news in store for loyalists of Microsoft&#8217;s internet browsing applications. \u201cThe software giant is set to release a new web browser code named Spartan with Windows 10. It will act as a total replacement of Internet Explorer and we expect it to have the most advanced technology available among web browsers,\u201d he said.<\/p>\n<p class=\"p2\">In November 2014 ESET Smart Security 8 scored 100% in a <a href=\"http:\/\/media.ne.cision.com\/l\/lhcemhho\/www.av-test.org\/en\/news\/news-single-view\/self-protection-for-antivirus-software\/\"><span class=\"s1\">study by AV-Test that focused on self-defence<\/span><\/a>. In its test, AV-Test examined the use of open-access protection mechanisms \u2013 ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) \u2013 within the source code of IT security vendors. Both mechanisms help to reduce the risk of an existing vulnerability actually becoming exploitable.<\/p>\n<p>&nbsp;    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Internet Explorer, Microsoft\u2019s ubiquitous web browser that remains one of the most used internet browsing applications worldwide, has topped a list of the most frequently targeted Windows components. Prepared by ESET, the report titled &#8216;Windows exploitation in 2014&#8216; also found that usage of Windows XP, the popular Operating System (OS) that is no longer supported [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":1074,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6],"tags":[],"class_list":["post-1073","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/1073","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=1073"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/1073\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/1074"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=1073"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=1073"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=1073"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}