While elevated privilege attacks remain a critical security concern when using Microsoft products, a new report says that the raw number of vulnerabilities is dropping. Credit: Martyn Williams/IDG The total number of Microsoft vulnerabilities reported in 2021 dropped by 5%, reversing a five-year trend that saw such vulnerabilities rising sharply, according to a new report from identity management and security vendor BeyondTrust.A total of 1,212 new vulnerabilities were discovered in 2021, but their severity, as well as their location in the Microsoft family of software products, has changed substantially year over year. Vulnerabilities rated as “critical” on the CVSS standard dropped by 47% in the past year, reaching their lowest levels since BeyondTrust began issuing this report, nine years ago.Vulnerabilities on Windows, Windows Server dropWindows and Windows Server both saw sharp drops in total vulnerabilities detected, by 40% and 50%, respectively, while vulnerabilities affecting Microsoft’s Edge and Internet Explorer browsers hit a record high. Assisting in the latest analysis is Microsoft’s move to NIST’s common vulnerability scoring system, which lets researchers cross-reference security flaws more directly with bugs in the outside ecosystem. The most common type of vulnerability seen in 2021 involved privilege elevation, where an attacker gains admin rights to a system through illicit means. A total of 588 such vulnerabilities were discovered in 2021. BeyondTrust’s researchers credit a more widespread adherence to good security practices for this rise — perversely, a general decrease in users with unnecessary admin privileges helped focus bad actors’ efforts on attempts to gain elevated privileges in different ways.Attackers innovate to gain admin rights“Without easy access to users with local admin rights, attackers have started to innovate to gain elevated privileges that can then be used to compromise systems, steal credentials, and move laterally,” the report said. The second-most common type of vulnerability centered on remote code execution, which is particularly dangerous since attacks targeting such flaws can be conducted remotely, with little or no user interaction required. A total of 326 of these vulnerabilities were found in 2021, 35 of which rated a 9.0 or higher on the CVSS scale.“With this type of risk, a workable exploit is not a matter of ‘does an exploit exist,’ but rather ‘when will it be publicly available,'” said the BeyondTrust report.The report also broke out vulnerabilities in key Microsoft products, including Azure, Windows and Microsoft Office. The latter saw just one critical vulnerability, compared to a total of 66 found in 2021, while the same numbers for Azure and Dynamics 365 were seven and 44, respectively.BeyondTrust’s researchers praised Microsoft’s consistent efforts to keep Azure safe, and lauded a “steady decline” in Office vulnerabilities. Similarly, the Windows operating system itself saw a 40% drop in total vulnerabilities in 2021 compared to the previous year, with a 50% drop in critical security flaws. Related content news UK’s revamped surveillance rules become law despite industry opposition A new law expanding the Investigatory Powers Act, the UK’s already-controversial surveillance and data access rules, became law last week. By John Leyden Apr 29, 2024 4 mins Government Mobile Security Security feature Finding the perfect match: What CISOs should ask before saying ‘yes’ to a job Sometimes it's not really clear why a company wants to hire a CISO or the role lacks authority. There are some key questions that CISOs can ask to avoid taking a job with too many red flags. By Aimee Chanthadavong Apr 29, 2024 8 mins CSO and CISO Careers opinion Navigating personal liability: post data-breach recommendations for CISOs CISOs can avoid being liable for data breaches by following legal advice, communicating effectively with internal and external stakeholders, and demonstrating commitment to avoid future incidents. By Daniel B. Garrie and Richard A Kramer Apr 29, 2024 8 mins CSO and CISO Data Breach Legal news 2024 CSO30 ASEAN Awards: Call for nominations By Xiou Ann Lim Apr 29, 2024 2 mins Security PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe