Internet Explorer was the most targeted Windows component by cybercriminals last year. In 2014 Microsoft also patched two times more vulnerabilities in the browser compared to 2013. Internet Explorer was also the target of 7 zero-day vulnerabilities.

Last year Microsoft patched 240 vulnerabilities in Internet Explorer, while the company issued 120 updates for the browser in 2013. Other Windows components like the kernel, kernel drivers, the .NET framework and Microsoft Office required less patch releases in 2014 than the year before. Nevertheless, some of the last year discovered leaks were abused in targeted attacks.
Microsoft has been working on improving the security of Windows and Internet Explorer, and the company is indeed improving, according to antivirus company ESET. Newer Windows version contain technologies that should make it harder to exploit vulnerabilities. Internet Explorer is now equipped with a full fledged sandbox and users can further harden their system and application security using Microsoft's Enhanced Mitigation Experience Toolkit (EMET).
Thanks to the increased security it will be harder to find vulnerabilities and develop exploits. "Due to the significant and increasing complexity of exploit development, we also can predict that such exploits will continue to be developed by specialist engineers for use in targeted attacks", according to ESET.
The company warns that lots of users are still on Windows XP, they take a security risk as the old operating system doesn't contain mentioned security technologies and doesn't receive security updates anymore.















