November 7, 2007

Yahoo Messenger, QuickTime top list of most vulnerable Windows apps

November 2nd, 2007

Posted by Ryan Naraine @ 8:35 am Software products marketed by Yahoo and Apple have topped the list of the most vulnerable Windows-based applications in 2007, according to endpoint security vendor Bit9.

The list, available here (registration required), focuses on popular, widely deployed Windows programs that are often very difficult for an IT department to locate or patch and, as Bit9 explains, “represent unexpected and unquantified vulnerabilities in an enterprise IT environment.”

[Gallery: Ten free security utilities you should already be using ]

Yahoo’s standalone IM client, which has been riddled with security holes all year, is #1 on the list. The buggy Yahoo Widgets software also makes an appearance at number 9.

Apple’s QuickTime media player and iTunes music download software also feature high on the list.

Strangely, Microsoft does not feature heavily on the Bit9 list. In fact, a Microsoft product appears only once on the list — Windows Live MSN Messenger at #4.

The Bit9 explanation:

The reason most Microsoft software doesn’t make the list is because by now most companies have a pretty good process in place for identifying, patching, and fixing vulnerable Microsoft software. The same cannot be said for apps cialis generic brand like Firefox, iTunes, and other packages.

That does make sense but it’s hard to imagine Internet Explorer 6, the world’s most widely used — and heavily targeted — browser, not making an appearance on this list.

I could also make the argument that Microsoft Word, which has struggled with zero-day attacks and multiple code execution hole, should be high on any list of most-vulnerable Windows apps.

Here’s the top-ten from Bit9:

  1. Yahoo! Messenger 8.1.0.239 and earlier
  2. Apple QuickTime 7.2
  3. Mozilla Firefox 2.0.0.6
  4. Microsoft Windows Live (MSN) Messenger 7.0, 8.0
  5. EMC VMware Player (and other products) 2.0, 1.0.4
  6. Apple iTunes 7.3.2
  7. Intuit QuickBooks Online Edition 9 and earlier
  8. Sun Java Runtime 1.6.0_X
  9. Yahoo! Widgets 4.0.5 and previous
  10. Ask.com Toolbar 4.0.2.53 and previous

As I always recommend for Windows users, be sure to scan your system for security holes and apply all the necessary patches. Secunia’s free Web-based software inspector is a great place to start. A downloadable version is also available.

Permalink • Print • Comment

Leave a comment

You must be logged in to post a comment.

Made with WordPress and a healthy dose of Semiologic • Sky Gold skin by Denis de Bernardy