Windows XP SP2 or Windows Vista - Which Did Better in 2007?
Wed, 2008-05-14 23:26
Topic(s):

You've been hearing the stories about how people just want to stick with Windows XP SP2, but Windows Vista security is supposed to be better.  Do you wonder how many vulnerabilities and patches each one had in 2007?

In the wake of my Windows Vista One Year Vulnerability Report, which compared the "first year of availability" of several products, I received many comments along the lines of "of course Windows Vista beats Windows XP as it shipped in 2001, but what about the current Windows XP SP2?"

I set out to answer this question, at least for 2007 and the result is a short paper analyzing vulnerability data for Microsoft Windows Vista and Microsoft Windows XP SP2 for calendar year 2007 and a brief analysis to see if any benefit is apparent for users of one OS over the other.  You can download the full paper here.

Here is the chart breaking down the vulnerabilities by Microsoft severity ratings

I found that Windows Vista offers benefit over Windows XP SP2 in the following ways for 2007:

  • Windows Vista had 30% fewer Security Bulletins than Windows XP
  • Windows Vista had 20% fewer vulnerabilities than Windows XP
  • Windows Vista had 28% fewer Critical and Important vulnerabilities than Windows XP
  • 26 vulnerabilities on Windows Vista are less severe for any users running as standard user

 

Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
E-GUIDE
Log Management in a Cyber World

ArcSight With so many potential cyber villains poking around the gates, enterprises must have strong protections and pristine visibility into what's happening on the network. Explore the increasing importance of log management as cybercrime and other malicious threats grow.

» Read this eGuide

WHITE PAPER
Comparing Research in Motion and Microsoft Mobile Solutions

Microsoft Organizations must look carefully at the requirements of mobile devices and accompanying middleware that can increase cost, complexity and administrative overhead. This white paper provides an independent analysis and detailed comparison of RIM and Microsoft's mobile solution.

» Read this White Paper