On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

March 22nd, 2007

90-day report card: Windows Vista fared better than competitors

Posted by Ryan Naraine @ 7:37 am

Categories: Apple, Browsers, Data theft, Exploit code, Hackers, Metasploit, Microsoft, Open source, Patch Watch, Pen testing, Punditocracy, Responsible disclosure, Vulnerability research, Windows Vista

Tags: Card, Red Hat Inc., Vulnerability, Microsoft Windows Vista, Jeff Jones, Microsoft Windows, Apple Mac OS X, Ryan Naraine

In Focus » See more posts on: Vista

Ninety days after the release of Microsoft's Windows Vista to business customers, the new operating system has a much better security vulnerability profile than its predecessor and several other modern workstation operating systems including Red Hat, Ubuntu, Novell and Apple products.

That's according to Jeff Jones, security strategy director in Microsoft's Trustworthy Computing group.

Vista 90-day security report

Jones has published a 90-day report card (.pdf), stacking up flaws reported and fixed in Vista against vulnerabilities covering during the first 90 days of Windows XP, Red Hat Enterprise Linux 4 WS, Ubuntu 6.06 LTS, Novell SUSE Linux Enteprise Desktop 10 and Mac OS X 10.4 (Tiger).

During the period under review, Jones said Microsoft shipped a solitary security bulletin affecting Vista users — MS07-010, which covered a remotely exploitable hole in the Microsoft Malware Engine.  He also called attention to four other reported Vista bugs that remain unpatched, one carring a "high risk" rating.

By comparison, during the first 90 days after Windows XP shipped, Jones research showed that Microsoft patched a total of 14 vulnerabilities, 8 rated critical.  "At the end of the 90 day period, a total of 4 publicly disclosed [Windows XP] vulnerabilities did not yet have a patch available from Microsoft," Jones said.

Regarding Red Hat Enterprise Linux 4 Workstation (rhel4ws), Jones said the open-source vendor fixed a total of 181 vulnerabilities, 58 rated "high severity" by the U.S. governments National Vulnerability Database.  He acknowledged that many of these bugs covered components that Red Hat ships and supports as Red Hat Enterprise Linux 4 WS, noting that it might be construed as "unfair" to count those.

However, even with RHEL4WS reduced component set, Jones said:

The reduced rhel4ws set of components had 86 vulnerabilities already publicly disclosed prior to general availability. Patches available on the first day of ship addressed 34 of these.

  • During the first 90 days, Red Hat fixed 137 vulnerabilities affecting the reduced rhel4ws set of components. 40 of those addressed were High severity.
  • At the end of the 90 day period, a total of 64 publicly disclosed vulnerabilities in the reduced set of components did not yet have a patch from Red Hat.

In the first 90 days after Apple's Mac OS X v10 shipped, Jones showed that Windows Vista fared much better, arguing that the data does not support Apple's marketing stance that the Mac OS X does not have the same security issues that face other operating systems.

Specifically, Jones reported that:

  • Mac OS X v10.4 had 10 vulnerabilities already publicly disclosed prior to the April 29, 2005 ship date and Apple provided fixes for 4 of these during the first 90 days after ship. Four of the vulnerabilities were High severity.
  • During the first 90 days, Apple fixed a total of 20 vulnerabilities affecting Mac OS X v10.4, of which 8 were rated High severity in the NVD.
  • At the end of the 90 day period, there Mac OS X v10.4 still had 17 publicly disclosed vulnerabilities that did not yet have a patch from Apple.

He also provided comparable numbers for Ubuntu 6.06 LTS and Novell's SUSE Linux Enterprise Desktop 10 (SLED10) to show that Vista's security vulnerability profile was noticeably better.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 228 Talkback(s)
The inane battle of 9 to 5 operating systems
Folks
The battle over turf whose traits are relatively insignificant in the overall IT value
package. Sand boxers, lite duty businesses that have availability requirements that 2
9s would ... (Read the rest)
Posted by: joelkruissink@... Posted on: 06/19/07 You are currently: a Guest | | Terms of Use
How can you conclude anything?  DemonX | 03/22/07
Added to that  Saurondor | 03/22/07
Seems you didn't notice  xuniL_z | 03/22/07
Notice what?  Saurondor | 03/22/07
I did counter you.  xuniL_z | 03/22/07
Hey Linux_Z - why don't you just kiss MS's ass and be done with it.  nomorems | 03/22/07
You didn't  Saurondor | 03/22/07
Then I'll counter it  NonZealot | 03/22/07
Still waiting NonZealot  Saurondor | 03/22/07
You've changed your question  NonZealot | 03/22/07
I didn't change a thing  Saurondor | 03/22/07
Here is the deal...  xuniL_z | 03/22/07
More FUD right xunil ! Still living in denial huh ?  Intellihence | 03/22/07
Looks like you are way off topic  xuniL_z | 03/22/07
How's about market share?  Solid Water | 03/22/07
This is too funny!  kodakmak | 03/23/07
Except that:  Suicida| | 03/24/07
Do you work for MS?  dolph0291 | 03/26/07
Yes  tomm174@... | 05/05/07
Dude Vista hasn't been around long enough to even get a grade .  Intellihence | 03/22/07
Did you read the article?  jshaw4343 | 03/22/07
Who's the shill?  rtk | 03/22/07
It's because  Futurdreamz@... | 03/23/07
intellihence  SO.CAL Guy | 03/24/07
And? So what?  HotPepperMan | 03/22/07
Open letter to "herronjames"...  Mike Cox | 03/22/07
LOL, that one was funny!  dragosani | 03/22/07
The jokes on you.  xuniL_z | 03/22/07
Mike Cox Finally Out-Coxed  Ole Man | 03/22/07
Was that  xuniL_z | 03/22/07
I beleive he assumed you were being sarcastic...  jjarman | 03/22/07
It's hard to tell with him.  xuniL_z | 03/23/07
Not really.  Futurdreamz@... | 03/23/07
in my case, really  xuniL_z | 03/23/07
Rah! Rah! Vista! Yay!!!  dolph0291 | 03/26/07
Also, Apple just did their "month of bugs" thing  jinko | 03/22/07
I have to use Vista  JEFFREY.JACOBSON@... | 03/23/07
really?  xuniL_z | 03/23/07
I think you're being unfair.  GuidoMuldoon | 03/24/07
Good post, Guido  Ole Man | 03/26/07
I am standing tall, feeling fine!  Mike Cox | 03/22/07
9.0  John L. Ries | 03/22/07
Awesome 9.0! (NT)  smartyram | 03/22/07
ummmm  xuniL_z | 03/22/07
Actually  Badgered | 03/22/07
right, that's why  xuniL_z | 03/22/07
ONE HUNDRED!!!!  xuniL_z | 03/22/07
4 million!  zkiwi | 03/24/07
9.9! I bow to the master  el1jones | 03/23/07
2.5  Futurdreamz@... | 03/23/07
The usual smoke and mirrors  bportlock | 03/22/07
Not really smoke and mirrors  Barndog | 03/22/07
Lets in 90 Days from Jan 30 about Vista.  mrlinux | 03/22/07
Vista is the most secure OS of all (including Unix, Linux and OS X)  zzz1234567890 | 03/22/07
Bookmarked  TripleII | 03/22/07
Vista at +120 days and counting  diane wilson | 03/22/07
Whatever you need  xuniL_z | 03/22/07
Precisely...  olePigeon | 03/22/07
Not smoke and mirrors  chrisfalter | 03/23/07
Hey! that made me realize something!  Futurdreamz@... | 03/23/07
I upgraded to Vista with NO PROBLEMS!!  BroGnorik | 03/22/07
Freudian slip?  Linux User 147560 | 03/22/07
And knowing where  xuniL_z | 03/22/07
Nice but weak attempt on your part...  Linux User 147560 | 03/23/07
While I don't have the  xuniL_z | 03/23/07
Older hardware  voska | 03/23/07
Where are your facts???  JEFFREY.JACOBSON@... | 03/23/07
OK; so what do the usual security types say?  John L. Ries | 03/22/07
one "usual security type" is pretty impressed  diane wilson | 03/22/07
Thanks  John L. Ries | 03/23/07
I work in security  voska | 03/23/07
I feel bad for the Mac zealots  NonZealot | 03/22/07
Zealot  dragosani | 03/22/07
NonZealot- Where is your response to this dragosani post  rolla_ifs@... | 03/22/07
MSZealot is awfully quiet  RealNonZealot | 03/23/07
*shakes head*  Stuka | 03/22/07
why dont you read the article  zzz1234567890 | 03/22/07
You misunderstood  Stuka | 03/22/07
Irony abounds  rushnrockt | 03/22/07
"non-Zealot"  hairyR | 03/22/07
You feel sooooooooooooooooo bad...........  jjarman | 03/22/07
He's off sobbing he feels so bad  TtfnJohn | 03/23/07
Don't feel bad.  People | 03/22/07
It's not just the everyday zdnet zealots.  xuniL_z | 03/22/07
it is resting  jjarman | 03/22/07
Oh now, be honest  IAHawkeye | 03/23/07
I said it once and I will say it again  BroGnorik | 03/23/07
Not so fast  TtfnJohn | 03/23/07
I don't know if..  msalzberg | 03/24/07
A Mac copy? Thiink again.  xuniL_z | 03/23/07
"xuniL_z and Zealot sitting in a tree...  MacCanuck | 03/23/07
Oh boy, here we go again.  xuniL_z | 03/23/07
Gee, thats funny...  MacCanuck | 03/23/07
Ok  xuniL_z | 03/23/07
free advice  josephmartins | 03/23/07
Total Idiot here...  usc1801 | 03/23/07
*sigh* ok, here goes again  xuniL_z | 03/24/07
Mac Zealots ?  tomm174@... | 05/05/07
When will we learn.  IAHawkeye | 03/22/07
Vista is not half bad  astawerksdotcom | 03/22/07
only a quarter bad?  jjarman | 03/22/07
Really poor "reporting"...on a really poor "study"  jjarman | 03/22/07
Again...did you read the article?  jshaw4343 | 03/22/07
Yes and Some Specifics...  jjarman | 03/22/07
I read the press release...  TtfnJohn | 03/23/07
no, it has a disclosure....  Linux Geek | 03/23/07
Now it's our turn to say...  Chad_z | 03/22/07
I agree  Badgered | 03/22/07
Vista already has more marketshare than Linux, OS X  zzz1234567890 | 03/22/07
Why do you keep pushing this fud?  TripleII | 03/22/07
After using Vista for 2 weeks....i just ordered a Mac  jjarman | 03/22/07
That's funny me too.  xuniL_z | 03/22/07
wow, sorry to hear it...  jjarman | 03/22/07
See, the only power I found on the Mac  xuniL_z | 03/23/07
Funny, my nephew is on his 3rd XBox 360  MacCanuck | 03/23/07
Wow, that is something  xuniL_z | 03/23/07
You miss the point as always  MacCanuck | 03/26/07
Hmmmmm  IAHawkeye | 03/23/07
whose making stuff up?  xuniL_z | 03/23/07
Also do not tell me that Vista can run on a Mac  xuniL_z | 03/23/07
Actually xuni  Kid Icarus-21097050858087920245213802267493 | 03/23/07
You had me till you said HP  voska | 03/23/07
Look at their laptops.  xuniL_z | 03/23/07
To the intellectually challenged paid-off troll  mg156 | 03/23/07
"Vista is dripping with coolness" Ha Ha!  Ole Man | 03/23/07
The numbers are not clear.  xuniL_z | 03/23/07
xunil_z, you're funny and  Kid Icarus-21097050858087920245213802267493 | 03/23/07
Full Of Crap, Yes  Ole Man | 03/23/07
Vista has low .93% Market share!  rolla_ifs@... | 03/22/07
They may have to choose windows, but XP is back.  TripleII | 03/22/07
Well then, what you are saying is  xuniL_z | 03/23/07
Mac Market share is very significant at least 6%  rolla_ifs@... | 03/23/07
You are wrong.  xuniL_z | 03/23/07
Even Vista's Cheif Covets OS X!, Intel Founders, etc Love Macs!  rolla_ifs@... | 03/23/07
What you are trying to sell  xuniL_z | 03/23/07
Perhaps the reason...  msalzberg | 03/24/07
So your definition of quality....  xuniL_z | 03/24/07
You love to  msalzberg | 03/24/07
xuniL_z... you're wrong and have been sold  MacCanuck | 03/26/07
"Vista has already been banned by two US government branches" Actually NOT  Michael L Hereid Sr | 03/23/07
You be surprised....  MacGeek2121 | 03/23/07
More insight from the wind  John Zern | 03/22/07
Even better in the original  ShawnaM | 03/22/07
URL for the original  ShawnaM | 03/22/07
There are lots of ways to manipulate security statistics.  jjarman | 03/22/07
Did anybody notice  jjarman | 03/22/07
Even better  frgough | 03/23/07
You're so right, jjarman  labarker | 03/23/07
No Malware for OS X  aristotle_z | 03/22/07
Sorry, STILL SUCKS  itanalyst | 03/22/07
just as a courtesy, even though you don't deserve it  xuniL_z | 03/23/07
Safer? I Think NOT  itanalyst | 03/22/07
Safer.......  Kobashrer | 03/22/07
Wow..This really Hurst Vista and Helps Apple and Redhat!  rolla_ifs@... | 03/22/07
Logic makes sense  spacecase2 | 03/22/07
You're coming to a sad realization -  nix_hed | 03/24/07
Open Source?  cmjrees | 03/24/07
Yes, Open source.  Rick_K | 03/24/07
Microsoft has serious math problems just like Intel  TechExec2 | 03/22/07
i think...  nix_hed | 03/24/07
VISTA SHIPS WITH A BOMB INSIDE IT!!!  TechExec2 | 03/23/07
Vista ships with a bomb  leewen@... | 03/23/07
Exactly!!!  SpikeyMike | 03/23/07
There hasn't been enough time or users to find the problems...  BitTwiddler | 03/23/07
ReI think the data here is quite invalid.  Kid Icarus-21097050858087920245213802267493 | 03/23/07
Who cares  voska | 03/23/07
Vista... security thru obscurity  MacCanuck | 03/23/07
Well aren't we...  xuniL_z | 03/23/07
And this if from the Guy who  xuniL_z | 03/23/07
I'm just using Windows users' reasoning  MacCanuck | 03/26/07
90-day report card  leewen@... | 03/23/07
Only 5 Bugs that have been reported  mwiley_z | 03/23/07
Stenography  jsinaiko@... | 03/23/07
MS reports Vista is the best...  donniebnyc@... | 03/23/07
More MS Pooie  greg@... | 03/23/07
Right!  hoiatl | 03/23/07
90 days includes pre-release  Resuna | 03/23/07
I completeley disagree ...  trial.manager@... | 03/23/07
Vista safer then OSX? Riiiiggght.  3dtodd | 03/23/07
VISTA, NOT ONLY SAFER, BETTER ALL AROUND  xuniL_z | 03/23/07
Vista crack, anyone?  Kid Icarus-21097050858087920245213802267493 | 03/23/07
Why Don't You Just Give Up?  Ole Man | 03/23/07
I know enough to ask you this.  xuniL_z | 03/23/07
How Would You Know?  Ole Man | 03/23/07
Nice move ole man  xuniL_z | 03/26/07
Curiosity killed the cat  Ole Man | 03/26/07
Ok...  cmjrees | 03/24/07
wait a sec  xuniL_z | 03/26/07
He's got nothing better to do  TtfnJohn | 03/23/07
Another Psychotic Intellectual  Ole Man | 03/23/07
Did I hear right, you said dripping. LOL  mg156 | 03/23/07
So tell us...  Rick_K | 03/25/07
As I understand it  xuniL_z | 03/26/07
"As I understand it"?  Ole Man | 03/26/07
VISTA, NOT ONLY SAFER, BETTER ALL AROUND  aussieblnd@... | 03/27/07
not worth the read  peterbk@... | 03/23/07
This is Called Propeganda  ultra.snapp@... | 03/23/07
OS like cars  Hey U | 03/23/07
Hahahahaha  DarkPhoenixFF4 | 03/23/07
Re: Hahahahaha  royalstream | 03/23/07
Industry leaders even choose OS X over Windows!  rolla_ifs@... | 03/23/07
A couple of problems  blarman_z | 03/23/07
A couple of problems  aussieblnd@... | 03/27/07
This pointless....  Asketill | 03/23/07
Pardon the pun here, but this is Apples to Oranges...  usc1801 | 03/23/07
Questions re: the upgrade  intj-astral@... | 03/23/07
The Significance of Vulnerabilities  beep.wot | 03/23/07
Like heck it's secure  drpadiyar | 03/23/07
The report is from within MS go figure  jimk_z | 03/23/07
5.7  nix_hed | 03/24/07
Windows Vista the future 64-bit choice regardless  erniem1970@... | 03/24/07
What would you expect?  devlin_X | 03/24/07
The real question is...  Zinn36 | 03/24/07
The real question is...  aussieblnd@... | 03/27/07
If Trustworthy Computing improves security...  3dguru | 03/25/07
It's becauase  Rick_K | 03/25/07
Big Understatement  Ole Man | 03/25/07
Big Understatement  aussieblnd@... | 03/27/07
Microsoft's security department tells me their own Vista product is safer?  HypnoToad72 | 03/25/07
But, but....  Rick_K | 03/25/07
A couple of problems  thumbknuckle | 03/26/07
90-day report card  remarquee | 03/26/07
Vista transition smooth  sales@... | 03/26/07
read a little closer  aussieblnd@... | 03/27/07
Objectivity  tomm174@... | 05/05/07
99% of all statistics are wrong.  OKJoe | 06/07/07
Not too bad  Suicida| | 06/17/07
The inane battle of 9 to 5 operating systems  joelkruissink@... | 06/19/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here