
Microsoft Security Response Center security engineer Matt Miller said that many of the zero-day vulnerabilities are ineffective in new versions of Windows 10.
Miller analyzed zero-day attacks from 2015 to 2019, focusing on whether attacks exploiting these vulnerabilities have become less common since the release of Windows 10. The report concluded that over 40% of zero-day attacks have failed to affect Windows 10 since 2015, due to security measures added to the latest operating system.
At the BlueHat security conference in Israel in February, Miller said that most Windows vulnerabilities are exploited as zero-days. These vulnerabilities are targeted by malicious actors either before Microsoft has a chance to release a patch or when companies fail to patch a security issue.
According to Miller, two out of three cases, the zero-day attack did not work with the latest Windows 10 updates. However, the fact remains that even one out of three times hackers were able to compromise the "most secure OS system."
A study conducted by the Ponemon Institute in 2018 showed that zero-day attacks, along with fileless attacks, were the most prevalent for businesses. While a large enterprise could create a patch fairly quickly, many small businesses don't have enough money to deploy patches in a timely manner. And every day that goes by without a patch comes at a financial cost to a company.
In October, a researcher discovered a zero-day vulnerability in Windows 10that allowed attackers to delete files without the user's permission. And although Microsoft responded quickly and patched the vulnerability, such attacks occur on a daily basis.
