ITASCA, Ill., Jan. 23, 2018 -- Flexera, the company that’s reimagining how software is bought, sold, managed and secured, today announced recommendations for a standardized, risk-based approach to managing vulnerabilities such as Spectre and Meltdown. Flexera’s three-pronged approach, based upon internal expertise around vulnerability remediation and intelligence harvested from Secunia Research’s Advisories, advises organizations to:
|
|||||
- Determine Criticality: Determine actual Spectre/Meltdown risk criticality using verified vulnerability intelligence
- Prioritize: Prioritize remediation of known vulnerabilities based on criticality – not hype
- Fix Using Conservative Mitigation Approach: Apply patches with an emphasis on testing in controlled environments
“There’s no doubt companies should be concerned about Spectre and Meltdown. But since these vulnerabilities came to light on January 3, Secunia Research at Flexera has published dozens of advisories on unrelated, highly critical vulnerabilities. If weaponized, exploitation of these vulnerabilities could have a devastating impact on organizations,” said Kasper Lindgaard, Director of Research and Security at Flexera. “With more than 17,000 vulnerabilities disclosed within the past year – how do organizations know where to allocate scarce IT sources to minimize risk? They need access to verified vulnerability intelligence and must take a common-sense, risk-based approach to applying patches. Otherwise they’ll be forever chasing shadows from one sensational news cycle to the next.”
Understanding True Spectre/Meltdown Risk
The Spectre and Meltdown processor vulnerabilities are documented in three CVE’s (CVE-2017-5754, CVE-2017-5753, CVE-2017-5715). While these vulnerabilities are indeed pervasive and potentially harmful – to truly assess risk CIO’s need deeper vulnerability intelligence (beyond a basic CVE score). This deeper intelligence should provide product context that takes into account attack vectors and possible security impact, allowing security teams to look beyond speculation commonly hyped by the media.
To date, Secunia Research at Flexera has issued more than 35 vulnerability intelligence advisories linked to Spectre/Meltdown, and most were scored below “Moderately Critical” (Criticality scores of 1 to 3 out of a maximum score of 5). This would suggest that while Spectre/Meltdown vulnerabilities are important – other more critical unpatched vulnerabilities within the environment could present a more immediate threat.
Prioritized Patching
Once CIO’s get an accurate understanding of the risk to their environments, they can put into place common-sense, risk-based remediation plans. This will ensure they’re prioritizing those risks and allocating scarce IT resources accordingly.
“Because of its massive scale, Spectre/Meltdown has dominated the headlines for the last couple weeks. But prudent CIO’s shouldn’t take their eye off the ball,” said Lindgaard. “By identifying the vulnerabilities that could pose the greatest harm and prioritizing remediation efforts to those first, organizations can most efficiently and cost effectively minimize risk.”
Conservative Mitigation
With risk and prioritization established, organizations should then apply patches with an emphasis on testing in controlled environments. Using established processes and tools to aid in identifying possible, unintended consequences ensures understanding ahead of time the potential performance hits and compatibility issues of patching.
“Patching is essential to reduce the attack surface, but it must be done prudently and with an understanding ahead of time of potential impacts on system performance and stability,” added Lindgaard. “Mitigation should happen carefully and conservatively, with a focus on risk-based models.”
Follow us on…
Resources:
Download the Vulnerability Review 2017
Learn more about:
About Flexera
Flexera is reimagining the way software is bought, sold, managed and secured. We view the software industry as a supply chain, and make the business of buying and selling software and technology asset data more profitable, secure, and effective. Our Monetization and Security solutions help software sellers transform their business models, grow recurring revenues and minimize open source risk. Our Vulnerability and Software Asset Management (SAM) solutions strip waste and unpredictability out of procuring software, helping companies buy only the software and cloud services they need, manage what they have, and reduce compliance and security risk. Powering these solutions and the entire software supply chain, Flexera has built the world’s largest and most comprehensive repository of market intelligence on technology assets. In business for 30+ years, our 1200+ employees are passionate about helping our 80,000+ customers generate millions in ROI every year. Visit us at www.flexera.com.
About Secunia Research at Flexera
Secunia Research at Flexera is a research team with globally recognized expertise in discovering, verifying, testing, validating and documenting vulnerabilities on tens of thousands of applications and systems. Our experts work under strict ethical guidelines and collaborate with the research community and software producers to guarantee the quality of the vulnerability information we document.
*All third-party trademarks are the property of their respective owners.
A photo accompanying this announcement is available at http://www.globenewswire.com/NewsRoom/AttachmentNg/8fd31111-f5a4-494e-995e-dc5f47ed8b40
For more information, contact: Flexera Amanda Ingalls (949) 241-1515 [email protected]


Uber Ordered to Pay $8.5 Million in Bellwether Sexual Assault Lawsuit
Nvidia Nears $20 Billion OpenAI Investment as AI Funding Race Intensifies
CK Hutchison Launches Arbitration After Panama Court Revokes Canal Port Licences
OpenAI Expands Enterprise AI Strategy With Major Hiring Push Ahead of New Business Offering
TSMC Eyes 3nm Chip Production in Japan with $17 Billion Kumamoto Investment
Alphabet’s Massive AI Spending Surge Signals Confidence in Google’s Growth Engine
Prudential Financial Reports Higher Q4 Profit on Strong Underwriting and Investment Gains
AMD Shares Slide Despite Earnings Beat as Cautious Revenue Outlook Weighs on Stock
TrumpRx Website Launches to Offer Discounted Prescription Drugs for Cash-Paying Americans
Nvidia, ByteDance, and the U.S.-China AI Chip Standoff Over H200 Exports
FDA Targets Hims & Hers Over $49 Weight-Loss Pill, Raising Legal and Safety Concerns
Ford and Geely Explore Strategic Manufacturing Partnership in Europe
SoftBank Shares Slide After Arm Earnings Miss Fuels Tech Stock Sell-Off
Instagram Outage Disrupts Thousands of U.S. Users
Australian Scandium Project Backed by Richard Friedland Poised to Support U.S. Critical Minerals Stockpile
Anthropic Eyes $350 Billion Valuation as AI Funding and Share Sale Accelerate
Sony Q3 Profit Jumps on Gaming and Image Sensors, Full-Year Outlook Raised 



