Study: Windows has fewest security holes

By Andy McCue, Special to ZDNet Asia
Monday, March 26, 2007 10:51 AM

Microsoft Windows has the lowest number of vulnerabilities and the fastest turnaround time for patches of all commercial operating systems--but it also has the most serious flaws, according to Symantec.

Despite having the fewest security holes, Windows was hit by more critical flaws than either Red Hat Linux or Mac OS X, Symantec found.

Symantec's latest "Internet Security Threat Report" (PDF) reveals 39 security holes were discovered in Windows during the second half of 2006, with an average patch development turnaround time of 21 days, up from the 22 Windows holes found in the first six months of the year.

Red Hat Linux had 208 vulnerabilities for the same period with an average patch time of 58 days, a huge increase on the 42 patched vulnerabilities for the first half of the year.

Apple's Mac OS X had 43 vulnerabilities--more than double the number for the first half of 2006--and an average patch time of 66 days.

But almost one-third of the 39 Windows holes were high severity, and 20 were medium severity. Just two of the 208 Red Hat Linux security holes discovered were high severity, with 130 medium severity and 70 low severity. Only one of the Mac OS X holes was considered high severity, with 31 classed as medium and 11 as low severity.

The report found that Windows also had the most vulnerabilities with exploit code and exploit activity, which Symantec claims may be one explanation why Microsoft has been pressured to develop and issue patches more quickly than other vendors.

Mozilla Web browsers, such as Firefox, are also more secure than Microsoft's Internet Explorer, according to the report.

It found 54 holes in IE during the second half of 2006, with one of these being of high severity, compared with 40 holes in Mozilla browsers, which had no high-severity vulnerabilities. Only four holes were found in the Safari and Opera browsers over the same period.

The latest Symantec threat report, which covers the six-month period from July 1 to December 31, 2006, also reveals the number of "zombie" PCs hijacked by hackers and used to launch denial-of-service attacks or send out spam has risen by almost 30 percent in the past year.

Arthur Wong, senior vice president for Symantec Security Response and Managed Security Services, said attack methods used by cybercriminals are becoming more complex and sophisticated to escape detection.

Andy McCue of Silicon.com reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 2 comments

Stop spreading FUD. This article is simply B.S., as is the study it refers to. You compare the number of flaws in Windows and in Fedora. Ok. But Windows come with a a restricted set of applications, whereas Fedora comes with more than 15.000 packages, and thousands of applications. You can't compare what's not comparable. And, most of these flaws do not concern the wide majority of users, since they affect programs that are only rarely used. Finally, you compare the average patching time: but you'd rather have long-to-come patches for low-risk vulnerabilities in unused packages, or high-risk vulnerabilities unpatched? Common, stop writting such articles, and think twice before you spread FUD.
Posted by anonymous on Tuesday, March 27 2007 04:50 AM

This kind of reporting is shameful and dangerous to the end user. People need to know the truth about Microsoft and their poor security record. The fact is that Windows is full of holes and there are many unpatched holes that Microsoft refuses to patch because by doing so will disable their "phoning home" and built in spyware features. This is why there are hundreds of thousands of viruses attacking and penetrating Windows every day. Windows has over a 100,000 viruses, spyware and trojan exploits, Linux has 0. Easy choice. Linux.
Posted by anonymous on Tuesday, March 27 2007 04:44 PM

Related Whitepapers


Tech Jobs Now!

Search for your ideal tech job:

Common ways IT wastes money on development

Web Development

Examples include using developers as support staff and failing to calculate a project's ROI before giving it the go-ahead.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions




Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web