Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


February 04, 2009

Microsoft Security Bulletins: Admin Rights Make Users Vulnerable

Taking the hassle out of Patch Tuesday
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

“Companies face imminent danger from zero-day threats as new vulnerabilities continually crop up while patching efforts lag behind, and even worse, many threats exist undetected,” says John Moyer, CEO of BeyondTrust. Even if you're not a customer of BeyondTrust, whose security solutions enable the security practice of least privilege, your common sense should tell you that removing a user's administrative rights should make the user less vulnerable to some security threats. But how much less vulnerable? How many security threats could be mitigated by removing users' administrative rights?

To find out, BeyondTrust analyzed Microsoft security bulletins issued in 2008, classified them by severity and vulnerability type, and tallied the number of bulletins where the Mitigating Factors section read, "Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights." The company found that 92 percent of the critical vulnerabilities Microsoft issued bulletins for could be mitigated by configuring users to operate without administrator rights. When it came to specific types of vulnerabilities, 87 percent of remote code execution vulnerabilities could be mitigated in this way. In the case of vulnerabilities exploiting Microsoft Office, Internet Explorer (IE), and Windows, removing user administrator rights could mitigate against more than three quarters of the Office and IE vulnerabilities and more than half of the Windows vulnerabilities.

"Our findings reflect the critical role that restricting administrator rights plays in protecting against these types of threats," Moyer says about the figures, available in the company's PDF white paper. "This is achievable in one simple step—adopting a strategy of Least Privilege security."

End of Article



Reader Comments
I WANT MORE OFWIN XP DESKTOP TROUBLESHOOTNG INFORMATION

murali76 June 14, 2009 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Industry Bytes
 
Industry Bytes
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Industry Bytes
Interop News: Datacom Unveils New 10Gb Data Filtering Taps and Switches
Make a Comment
Tony Redmond's Top 10 Things About Exchange 2010

Last Comment
In defense of Tony's list, remember that it's "Top 10 Things You Need to Know About Exchange 2010," ...
(3 Comments)
Hire Better Employees with This 5-Step Process
Make a Comment
MOSS 2007 and SharePoint 2010: Walking the line between past and future
Make a Comment
Notes from the Hiring Table, Part 4: Become the Ultimate Employee
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement