What is a software vulnerability?
A vulnerability is a weakness in software that an attacker can use. Where they come from, how a patch closes one, and how fast to install it.
A software vulnerability is a weakness in a program or operating system that an attacker can use to do something they should not be able to do, such as read your files or run their own code on your computer. It is usually a mistake in how the software was designed or written, and it can sit unnoticed for a long time.
Where vulnerabilities come from
The UK’s National Cyber Security Centre sorts them into three kinds.
- Flaws. The software does something its makers never intended, because of a design or coding mistake. Most common attacks use flaws.
- Features. The software works as intended, but the feature can be misused. Macros in Microsoft Office are the usual example.
- User error. Someone leaves a default password in place, switches on a risky setting or does not apply a fix that was available.
How a patch closes one
When a software maker learns of a vulnerability in its product, it usually releases a patch: an update that fixes the weakness. Once you install the patch, that way in is closed on your device.
Releasing the patch also tells the world where the weakness was. The Australian Signals Directorate (ASD) warns that once a vulnerability in an online service is made public, attack code can be expected within 48 hours, and sometimes within 24. Attackers may then keep targeting the same weakness for months or even years after the update is available.
So the time that matters is the gap between the patch coming out and you installing it. Automatic updates keep that gap short, and CISA, the United States cyber security agency, recommends turning them on wherever they are offered.
How quickly to patch
Patching applications and patching operating systems are two of ASD’s Essential Eight. Its guidance sets these times:
- Online services, and servers and network devices that face the internet: within two weeks, or within 48 hours if the maker rates the vulnerability as critical or a working attack exists.
- Commonly targeted applications: within two weeks.
- Staff computers, and servers that do not face the internet: within one month.
If time is short, ASD’s order is internet-facing systems first, then important servers and the computers of high-risk staff such as managers, finance and administrators, then everything else.
Software that no longer gets patches
Makers stop supporting old products. This is called end of life. From that day, new vulnerabilities in the product are never fixed. CISA’s advice is to retire end-of-life products. An old server, an out-of-date website plugin or a router the maker has dropped are common examples in a small office.
What to check or ask
- Are automatic updates on for every computer, phone and application?
- Who updates the things that do not update themselves, such as the router, the server and the website?
- Is anything we rely on past its end of life?
- How would we find out that a patch failed or is waiting on a restart?
For a website, Why neglected WordPress plugins become a security risk covers the same problem. If you would like someone to find the missing patches for you, that is what a vulnerability assessment does.
Sources
- Vulnerability: glossary definition (NIST Computer Security Resource Center) csrc.nist.gov
- Understanding vulnerabilities (UK National Cyber Security Centre) ncsc.gov.uk
- Understanding Patches and Software Updates (CISA) cisa.gov
- Patching applications and operating systems (Australian Signals Directorate) cyber.gov.au
- Essential Eight explained (Australian Signals Directorate) cyber.gov.au