Microsoft to offer more detailed security risk information
No one knows for certain how likely they are to be victimized by malware, but since 2008 Microsoft has been trying to give customers a rough idea of the risks they face with its “Exploitability Index,” a rating system released in conjunction with the monthly Patch Tuesday security updates.
After getting the patches, IT administrators could see ratings such as “consistent exploit code likely” – the most serious one – as well as “inconsistent exploit code likely” and “functioning exploit code unlikely.” This reflects the risk of attack in the 30 days immediately following the patch release.
Along with the vulnerability ratings – low, moderate, important or critical – this was designed to help customers prioritize deployment of security updates. But this system didn’t always accurately reflect the differences in the severity of threats posed to old and new versions of the same software, so Microsoft announced today that it will get more specific starting next week.
Each vulnerability will now have two Exploitability Index ratings – one for the most recent version of the software and another for older versions. Windows, Office and all other Microsoft products can be affected by monthly patches.
“This change makes it easier for customers on recent platforms to determine their risk given the extra security mitigations and features built in to Microsoft’s newest products,” Microsoft explained today. Windows 7, for example, makes it harder for attackers to write exploits with a technique Microsoft calls “Address Space Layout Randomization, … which repositions code fragments in memory.”
Not that Microsoft recommends indefinitely delaying patches, but the new rating system would let users of the newest Microsoft software know when they’re at less risk than users of older versions. Over the past eight months, there were 97 security problems that were less serious or not applicable to the latest version of a Microsoft product, out of 256 total. “In contrast, only seven cases affected the most recent product version and not the older platforms,” Microsoft said.
Microsoft is also making a second addition to the Exploitability Index related specifically to the risk of Denial of Service attacks. DoS attacks will be classified as “permanent” or “temporary.” This reflects the difference between a system needing to be restarted or recovering on its own, and may determine whether a service will go down in the face of attack. A “permanent” rating could even mean that a system will become unavailable when an attacker attempts to exploit a service but fails.
“In the case of remote code execution vulnerabilities, an issue that is difficult to exploit may still be used to crash a computer,” Microsoft said. “Even when an attacker cannot control memory addresses sufficiently to execute code, he may still be able to corrupt memory sufficienlty to stop the computer from responding.”
We’ll get the first taste of the new rating system on Tuesday, but it will be a light month for Microsoft patches. The advance notification shows two security updates, a critical bulletin affecting Windows Server and an important one affecting Office. Both involve remote code execution.




