advertisement
advertisement

Microsoft Wins Longest Exposure Time For A Security Patch: 5-And-A-Half Years

Written by Evan Schuman
February 23rd, 2010

When a security problem is discovered, timely response is important. So is making sure that the patch is going to fix the problem while also–hopefully—not introducing any new issues. That process takes time, and that’s OK. But someone at the Open Source Vulnerability Database took the time to see which vendor waited the longest to fix a glitch once it was discovered. No surprise: Microsoft took top honors, with an awe-inspiring 2,027 days. Yes, that’s more than 5.5 years.

Microsoft’s entry was its Microsoft Windows SMB NTLM Authentication Credential Replay Remote Code Execution. Apple was the next major name on the list, at 390 days, for its Mac SLP v2 Service Agent (slpd) Registration Request Overflow. Others who made the dishonorable list including Novell, Sun, HP and Computer Associates. The full list is absolutely worth reviewing.


advertisement

Leave a Reply

Readers, specifically those who want to comment on a story:
Our Comment SPAM system is getting very aggressive these days and has been blocking legitimate comments. If you post a comment and don't see it appear within 2 hours or so, can you please send a heads-up to customer-service@storefrontbacktalk? Ideally, please include the time you posted the comment. That will allow us to try and hunt for it. Thanks! P.S. We're working on fixing the system, but we don't want to lose any valuable comments in the meantime.

Weekly, Monthly Newsletters

Quickly catch-up on the latest in E-Commerce and Retail Tech with our free weekly report, with urgent bulletins as news merits—along with our monthlies on Mobile, Security, In-Store, E-Commerce and CRM.
advertisement

Most Recent Comments

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.