At the top of the list is Internet Explorer as the most vulnerable point of the Windows that is most frequently attacked.
ESET has published a report on the top exploit and threat mitigation trends in Windows in 2014 on its news page WeLiveSecurity.com.
In the report, ESET researchers analyze the most significant vulnerabilities in Microsoft Windows, compiling a list of the most frequently attacked Windows components. Internet Explorer is at the top of the list.
Compared to the previous year's results, the number of exploit attacks on Microsoft components appears to have increased in 2014. "This year was particularly tough for Internet Explorer users, as Microsoft disclosed twice as many vulnerabilities compared to 2013," ESET Research team reports on WeLiveSecurity.com. "Fortunately for its users, a large number of these vulnerabilities were patched during the year itself.".
The most well-known example of an Internet Explorer vulnerability in the wild is the Unicorn bug. ESET researchers also revealed their findings on the BlackEnergy trojan, which exploits a bug in Microsoft PowerPoint, at the 24th Virus Bulletin Conference in Seattle in September 2014.
The report includes information not only on the main types of vulnerabilities that have appeared over the past year in Microsoft Windows, but also on the mitigation techniques that Microsoft has introduced with the latest versions of its operating systems. “Unfortunately, many users are still using Windows XP without security features that would protect them from exploits, and therefore these users are constantly at risk of infection,” adds the ESET Research team.
In November 2014, ESET Smart Security 8 achieved a 100% score in an AV-Test self-defense survey. In these tests, AV-Test examined the use of open-source protection mechanisms – ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) – within the security software’s source code. Both mechanisms help reduce the risk of exploiting an existing vulnerability.
More information is available in the relevant blog post on WeLiveSecurity.com. The full report “Windows Exploitation and Mitigation in 2014” is available in the White Paper category on WeLiveSecurity.com.
Source: Newsbeast.gr
