Report: 92 Percent Of Critical Microsoft Vulnerabilities Are Mitigated By Eliminating Administrator Rights

BeyondTrust Corp. recently published research findings stating that the removal of administrator rights from Windows users is a mitigating factor for the vast majority of all Microsoft software vulnerabilities reported by Microsoft in 2008.

The results demonstrate that by configuring users as standard users, companies can better protect themselves against malware and zero-day threats. Complete findings and methodology can be found online in a new report, titled “Reducing the Threat from Microsoft Vulnerabilities.”

BeyondTrust’s findings show that among the 2008 Microsoft vulnerabilities given a “critical” severity rating, 92 percent shared the same best practice advice from Microsoft to mitigate the vulnerability: “Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.”

This language, found in the “Mitigating Factors” portion of Microsoft’s security bulletins, also appears as a recommendation for reducing the threat from nearly 70 percent of all vulnerabilities reported in 2008.

Other key findings from BeyondTrust’s report show that removing administrator rights will better protect companies against the exploitation of:

  • 94 percent of Microsoft Office vulnerabilities reported in 2008.
  • 89 percent of Internet Explorer vulnerabilities reported in 2008.
  • 53 percent of Microsoft Windows vulnerabilities reported in 2008.

Further illustrating the benefits to enterprises of removing administrator rights from users, a recent Gartner report states: “The Gartner TCO model shows a significant reduction in TCO between a managed desktop where the user is an administrator, compared with a desktop where the user is a standard user. Among the most remarkable observations is that the model shows a 24 percent decrease in the amount of IT labor needed for technical support.”

The complete report can be viewed at http://www.beyondtrust.com/documentation/whitePapers/wp_VulnerabilityReport.pdf.

Featured

New Products

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.