Windows 7 or Windows 10? A new study conducted by RiskBased Security and analyzing vulnerabilities observed in 2016 reveals that last year, Microsoft patched a greater number of security holes than in 2015. These bugs concerned Internet Explorer, Edge and of course the Windows 10 operating system.
Specifically, the study shows that last year, Microsoft patched a total of 729 vulnerabilities in its software, while in 2015 it patched 703. What is more worrying, of course, is that this number is almost double the number of vulnerabilities in 2014, when Microsoft found and patched 383 security holes.
The research also shows that Internet Explorer is still Microsoft's most vulnerable application. An all-time chart shows that the company's browser has had 1,261 flaws to date.
Surprisingly, Windows 10, which is marketed as the company's most secure operating system, was ranked first in the bug fix ranking with 705 vulnerabilities. Windows 10 was released in July 2015 and completed one year on the market in 2016.
Windows Server 2012 ranks third with 660 vulnerabilities, while Windows 7 is in fourth place with 647 bugs. Windows Vista is in fifth place with 621 security holes that have been patched.
Microsoft has said that upcoming builds of Windows 10 will be able to protect users from zero-days, even if there is no patch available. Recently, the company revealed that the Windows 10 Anniversary Update, released in August 2016, managed to block attacks that aimed to exploit unpatched vulnerabilities in the operating system. This means that users of the operating system were safe before Microsoft released a fix.
Furthermore, Microsoft has already begun downgrading Windows 7, explaining that it is a less secure operating system than Windows 10, citing that 10's security features make up for the obvious technical limitations of its predecessors.
_______________________
To play the devil's advocate a little, Microsoft is once again making empty promises while the numbers say otherwise. Of course, with all these promises, it is trying to promote its new product, and we have seen that it often uses completely unorthodox methods.
However, what no research, no prediction, and no promise can define is the reaction of the opposing side. Microsoft may promise more secure upcoming releases, but did it ask hackers?
