In their regular quarterly report the experts at Kaspersky Lab examined the changes to the IT-threat landscape throughout Q3 2012. Of particular note were high-profile cyber-espionage investigations, changes to the geography of threats, and a shake-up of the top 10 vulnerabilities.
An average of eight different vulnerabilities was detected on each vulnerable computer. The two most frequently used vulnerabilities were in Oracle Java products found on 35% and 21.7% of affected computers respectively. The top 10 also includes five Adobe products, two Apple products – QuickTime player and iTunes – and the popular Nullsoft Winamp media player. The automatic updates mechanism introduced into recent versions of the Windows OS means Microsoft products no longer feature in the top 10.
Among the 30,749,066 vulnerable programs and files detected, the top 10 vulnerabilities are listed below:
Adobe Flash Player Multiple Vulnerabilities
Adobe Flash Player |
Secunia ID – Unique vulnerability number: SA 41917
What the vulnerability lets malicious users do: Gain access to a system and execute arbitrary code with local user privileges; Bypass security systems; Gain access to sensitive data
Percentage of users on whose computers the vulnerability was detected: 9.70%
Date of latest change: 09.11.2010
Rating: Extremely critical