I'm concerned about the recent spike in Microsoft Silverlight attacks. How much of a threat does Silverlight p...
Unpatched applications on desktops are one of the most significant challenges in securing traditional client systems, leaving enterprises vulnerable to exploits that could and should be patched to stay secure.
In a blog post, Cisco security researcher Levi Gundert described a popular exploit kit that includes a Silverlight exploit. It was distributed via malicious ads, and the Silverlight vulnerability was used in the exploit to run malicious code on the endpoint. Silverlight has gained market share and is installed on more computers nowadays, so attackers decided it was worth their time to add Silverlight exploits to their exploit toolkits.
The increased use of Silverlight in exploit kits could be attributed to the fact that attackers identified that Silverlight was not being patched regularly and realized that awareness of the software was relatively low, making it an ideal target. Now that Silverlight has been included in a successful exploit kit, other attacks will follow suit and Silverlight will likely start showing up in other exploit kits and be used in more attacks.
When it comes to defending against attacks using Silverlight, addressing only the additional risks from vulnerabilities in Silverlight is ineffective if the other applications installed on a system are not also being kept up to date. Silverlight, like all applications, will require a security patch to address issues that may be exploited in an attack.
When patches are released, enterprises should plan on installing them for all of the systems with sensitive data in a regular and comprehensive cycle. Only installing operating system patches is not sufficient; enterprises should also evaluate their desktop patching process to validate that Silverlight is being patched.
Until organizations keep Silverlight -- and all other applications and systems -- patched and up to date, hackers will continue to exploit the vulnerabilities in it.
Ask the Expert!
SearchSecurity expert Nick Lewis is ready to answer your enterprise threat questions -- submit them now! (All questions are anonymous.)
Dig Deeper on Emerging cyberattacks and threats
Related Q&A from Nick Lewis
Cloud penetration testing presents new challenges for information security teams. Here's how a playbook from the Cloud Security Alliance can help ... Continue Reading
Many cloud providers are tight-lipped about internal security control details. Learn how to evaluate cloud security providers with certifications and... Continue Reading
Enterprises new to the cloud can write new security policies from scratch, but others with broad cloud usage may need an update. Consider these ... Continue Reading