HomeSecurityHow dangerous are zero day vulnerabilities really?

How dangerous are zero day vulnerabilities really?

vulnerabilities

In the world of the internet, a significant portion of consumer security measures are aimed at zero-day. A zero-day is a vulnerability that was previously unknown and has not been patched by the vendor. However, security teams need to ask themselves whether focusing on zero-day attacks is really the best use of operational resources.

Too bad for nothing

Despite all the fuss about zero-day vulnerabilities, the most devastating breaches are not caused by zero-days. Major breaches, such as the Equifax and WannaCry, were caused by vulnerabilities that were known to security teams at the time of the attack.

For example, the Equifax breach began with attackers simply scanning the web for servers vulnerable to the Apache Struts vulnerability (CVE-2017-5638). They found that there was a vulnerability in the Equifax dispute portal servers. Using requests from these servers, the attackers gained access to 48 other databases. Apache released a patch for this vulnerability on March 8, 2017, while it was May 13, 2017 when the hackers executed their plan. So, if Equifax had patched the vulnerability anytime before May 13, 2017, this breach would not have occurred.

A similar story happened with WannaCry. Two months before the attack, on March 14, 2017, Microsoft released the MS17-010 bulletin for EternalBlue along with patches for all supported versions of Windows. However, when the attack occurred in May 2017, many Windows systems were left unpatched or running unsupported operating systems, such as Windows XP.

In both of these cases, a simple patch of the already known vulnerability would prevent the theft of millions of personal files and significantly reduce the financial losses.

By focusing more on zero-day vulnerabilities, companies are not only missing the mark, but also ignoring the reality that the vast majority of attacks exploit known vulnerabilities. Roger Grimes, a security analyst, notes that most Microsoft customers have been hacked using vulnerabilities that were patched years ago.

As of April 2019, the Zero Day Initiative reported 89 Zero Day vulnerabilities for 2019. Compared to the 2634 known vulnerabilities for 2019 to date, Zero Day vulnerabilities represent just 3% of all vulnerabilities for the year. Patch management is the tried and tested best solution for protecting systems from attacks and breaches.

An undiscovered flaw does not make it a greater threat than a known flaw. As the Equifax breach shows, hackers are interested in finding organizations that have not patched known vulnerabilities. Hackers need to make the best use of their time and resources, and trying to exploit known vulnerabilities is often the best thing they can do than look for new ones.

Properly managing a vulnerability will eliminate most of the risk an organization faces from cyberattacks. Focusing on known vulnerabilities will have a much greater impact on protecting the organization. However, recognizing the threat posed by known vulnerabilities is only one aspect of adopting a proper vulnerability management program. The next step is prioritizing and remediating them.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS