Return
Understanding security risks in update mechanisms of computing systems
A
M
DOI:10.1016/j.cose.2026.105019.png)
Abstract
En 中文
This paper presents a study of update-related vulnerabilities based on a curated dataset of disclosures from the past decade. We analyze the exploitability, impact, and severity of these vulnerabilities, comparing them with the broader population of disclosed vulnerabilities. Our findings reveal that update-related vulnerabilities tend to be more severe and impactful, with a higher concentration of high-severity scores and a greater compromise of confidentiality, integrity, and availability. In contrast to general vulnerabilities, which are often network-exploitable, most update-related attacks require local access. We identify and categorize the most common weakness types in update mechanisms. We find that the most frequent weaknesses include authentication and authorization-related weaknesses, input-related weaknesses, path-related weaknesses, and certificate-related weaknesses. Furthermore, we introduce a rule-based approach with predefined keywords that assign vulnerabilities to six target-system classes. The classification relies on textual vulnerability descriptions together with vendor and product metadata. Finally, based on our analysis, we derive a set of clear mitigation recommendations to help secure update processes and reduce associated risks.
Keywords:
Secure updates
Software updates
Firmware updates
Vulnerability analysis
Target-system classification
Mitigation recommendations
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
C
IF:
5.4
Papers:
164
Citations:
0
Organization
No organization information available
