The Average Windows 10 PC Has 14 ‘Weaponized’ Vulnerabilities, New Research Finds

New research, published today, gives food for thought. That food might well leave you feeling somewhat nauseous, however, if you happen to be a Windows 10 user. The report, ‘Prioritization to Prediction (volume 5): In Search of Assets at Risk‘, seeks to make some sense of the comparative risk surface of devices based on which operating system they are using.

Unsurprisingly, the research found that regardless of whether that operating system was from Apple or Microsoft, Linux and Unix platforms, or even Internet of Things appliances and other network devices, vulnerabilities were pretty much everywhere. But it’s the Windows 10 numbers that surprised me, and I’ve been hanging around the cybersecurity business for more years than I care to recall.

Crunching the vulnerability numbers

Those vulnerability counts will vary depending upon the precise “asset mix” you are talking about. Still, by crunching the numbers from nine million devices across 450 organizations, Kenna Security was able to put things into some context. Some rather disturbing context from the security perspective as far as Windows is concerned.

For more than half of those organizations, Windows 10 devices comprised 85%, or more, of the total assets being used. You would expect, given the number of machines involved, the vulnerability totals to be on the high side. I didn’t expect them to be quite as high as this study suggests, though.

According to Kenna Security, the total number of vulnerabilities on Microsoft machines came in at 215 million. I felt a but coming on at this stage, which was quickly answered by the next statistic: 179 million had already been patched. Which would be great were it not that this meant some 36 million vulnerabilities were still unpatched.

How does Microsoft stack up against Apple, Linux and Unix?

If you were hoping for the numbers to improve, there’s more bad news for Windows fans. That 36 million unpatched vulnerability total is more than those found on Linux, Mac, Unix and network devices combined.

To clarify, more than the total number of patched and unpatched vulnerabilities combined.

When talking specifically about Windows 10 PCs, the average number of weaponized vulnerabilities was 14 per desktop. That’s 14 open vulnerabilities with known exploits.

Of course, as the report explains, not all these machines will be internet-facing so that an attacker could probe them for vulnerabilities to exploit. And when it comes to the exploits, the research doesn’t differentiate proof-of-concept exploits from those already integrated into the tools such as Metasploit that are used by penetration testers and hackers alike.

It’s not all bad news for Windows

There is some more good news for Windows users to be found in the research. Most notably that the Microsoft machines were patched quickly.

Talking of which, network devices tend not to have as many vulnerabilities per month, an average of 3.6, but they took 369 days, again on average, to fix.

The speed at which Microsoft fixes critical vulnerabilities is remarkable

“With automated patching and Patch Tuesdays, the speed at which Microsoft is able to fix critical vulnerabilities on their systems is remarkable,” says Wade Baker, partner and founder at Cyentia Institute, which performed the independent data analysis for the report. Baker warned that things like routers and printers could have high-risk vulnerabilities with a much longer shelf life. “Companies need to align their risk tolerance, strategy, and vulnerability management capabilities around these trade-offs,” he concluded.

To which Ed Bellis, CTO at Kenna Security, added, “Some assets have fewer vulnerabilities. Some assets receive lightning-fast patches. These groups don’t really overlap. The data we’re sharing can help enterprise IT and security better decide how to prioritize asset-based risk in their own environments.”

At the end of this particularly complex security day, it all comes down to your appetite for risk tolerance and understanding of the strengths and weaknesses of each platform. Windows-based machines will, without a doubt, it would appear, expose your business to the most significant risk surface in terms of vulnerability numbers. But they will also maximize your chances of fixing those vulnerabilities in the shortest possible time, so shrinking the attack surface quickly.

Hey, nobody ever said that security was easy…

Hot this week

The Hidden Security Benefits of a Tiny Website

Keeping your website under 14KB improves security by reducing abandonment to phishing sites and strengthening infrastructure resilience, especially in regions with poor connectivity.

DuckDuckGo Lets You Filter AI Images From Search Results

DuckDuckGo now allows hiding AI generated images in search results, giving users control over their visual experience while promoting media literacy.

Windows 11 Self Healing and Quick Recovery Explained

Windows 11's new self-healing feature helps systems recover automatically, but smart backup strategies remain essential for true resilience against attacks.

Mental Health Apps and Privacy Concerns

Understanding privacy risks in mental health apps and practical steps to protect sensitive emotional data while accessing digital support.

Weak Passwords Still Cause Massive Data Breaches

The McDonalds job applicant data leak shows how simple passwords like 123456 can expose millions to risk, demanding immediate personal security actions.

Topics

The Hidden Security Benefits of a Tiny Website

Keeping your website under 14KB improves security by reducing abandonment to phishing sites and strengthening infrastructure resilience, especially in regions with poor connectivity.

DuckDuckGo Lets You Filter AI Images From Search Results

DuckDuckGo now allows hiding AI generated images in search results, giving users control over their visual experience while promoting media literacy.

Windows 11 Self Healing and Quick Recovery Explained

Windows 11's new self-healing feature helps systems recover automatically, but smart backup strategies remain essential for true resilience against attacks.

Mental Health Apps and Privacy Concerns

Understanding privacy risks in mental health apps and practical steps to protect sensitive emotional data while accessing digital support.

Weak Passwords Still Cause Massive Data Breaches

The McDonalds job applicant data leak shows how simple passwords like 123456 can expose millions to risk, demanding immediate personal security actions.

FTC Moves to Simplify Subscription Cancellations

The FTC proposes new rules requiring one-click subscription cancellations and annual reminders, shifting power back to consumers in the digital marketplace.

AI Reshaping Operating System Development

New research shows how AI-experienced developers are creating more secure operating systems, with actionable insights for development teams worldwide.

When AI Tools Slow Down Cybersecurity Experts

Experienced cybersecurity professionals often work slower with AI tools due to verification needs. Learn actionable strategies to balance human expertise with AI assistance.
spot_img
Exit mobile version