back

by tzury·18y ago·view on hn ↗
Just wondering about IIS, IE, MS SQL Server, MS Exchange, NtOsKernel.dll, OutlookExpress, MS Outlook, MS Office VBA macros, WSH (vbs/js), COM/OLE, ActiveX, and the list goes on...

All major security holes and vulnerabilities founded so far in these products are 3rd party?

1 comments
No, but security defects are found in these bits less frequently than in their ISV competitors. There's been one remote found in IIS 6 in the last 2 years; none in IIS 7.

[edit] lemme correct myself --- there's been one remote that you heard about found in IIS --- the rest, Microsoft paid a shitload of money to find privately.