HomeSecurityThese are the top ten security vulnerabilities that hackers exploit the most

These are the top ten security vulnerabilities that hackers exploit the most

Security vulnerabilities in Microsoft software have become an even more popular means of attack by cybercriminals – but the Adobe Flash vulnerability still ranks as the second most used exploit by hacking groups.

hacker hacker

Analysis by researchers at Recorded Future of exploit kits, phishing attacks, and malware developed during 2018 found that flaws in Microsoft products were the most consistent target during the year, accounting for eight of the top ten vulnerabilities. That number is up from seven during the previous year. Patches are available for all of the flaws on the list — but not all users update their applications, leaving them vulnerable.

Microsoft is the most common target, probably thanks to how widespread its software is. The top vulnerability on the list is CVE-2018-8174. Nicknamed Double Kill, it's a remote code execution flaw distributed in Windows VBSscript that can be exploited via Internet Explorer.

Double Kill was included in four of the most powerful exploit kits available to hackers – RIG, Fallout, KaiXin and Magnitude – and helped deliver some of the most notorious forms of trojans and ransomware to unsuspecting victims.

But the second most frequently observed vulnerability during the year was one of two that didn't target Microsoft software: CVE-2018-4878 is an Adobe Flash zero-day that was first identified last February.

An emergency patch was released within hours, but a large number of users did not apply it, leaving their systems open to attack. CVE-2018-4878 has since been included in several exploit kits, most notably the Fallout Exploit Kit used for the GandCrab ransomware – the ransomware remains prolific to this day.

Adobe exploits used to be the most commonly used vulnerabilities by cyber hackers, but they seem to be moving away from them as we approach 2020.

Third on the most widely reported list of vulnerabilities is CVE-2017-11882. It was discovered in December 2016 and is a security vulnerability in Microsoft Office that allows arbitrary code execution against a maliciously modified file with the file – putting users’ computers at risk of malware. CVE-2017-11882 has been associated with various malicious campaigns, including the QuasarRAT trojan, the prolific Andromeda , and many others.

Very few vulnerabilities remain in the top ten year-on-year. CVE-2017-0199 – a Microsoft Office vulnerability that can take control of an affected system – was the most frequently exploited by cybercriminals in 2017, but fell to fifth place in 2018.

CVE-2016-0189 was the number one vulnerability in 2016 and the number two in 2017, and it continues to rank among the most frequently exploited. The Internet Explorer zero-day is still going strong nearly three years after it first appeared, indicating that there is a real problem with users not applying updates to their browsers.

Implementing appropriate remediation measures in operating systems and applications can go a long way in protecting organizations from some of the most commonly deployed cyber attacks.

"The biggest discrepancy is the importance of knowing the vulnerabilities being sold in underground and dark web forums," Kathleen Kuczma, a sales engineer at Recorded Future, told ZDNet.

“While the ideal situation would be to patch everything, having an accurate picture of the vulnerabilities affecting a company’s most critical systems, coupled with which vulnerabilities are being actively exploited or deployed, allows vulnerability management teams to better prioritize the most important places to patch,” she added.

The only non- Microsoft besides the Adobe vulnerability is CVE-2015-1805: a Linux kernel vulnerability, which is often used to attack Android smartphones with malware.

The ten most commonly exploited vulnerabilities according to the Recorded Future Annual Vulnerability report are:

  1. CVE-2018-8174 – Microsoft
  2. CVE-2018-4878 – Adobe
  3. CVE-2017-11882 – Microsoft
  4. CVE-2017-8750 – Microsoft
  5. CVE-2017-0199 – Microsoft
  6. CVE-2016-0189 – Microsoft
  7. CVE-2017-8570 – Microsoft
  8. CVE-2018-8373 – Microsoft
  9. CVE-2012-0158 – Microsoft
  10. CVE-2015-1805 – Google Android
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS