Saying that it doesn't test client-side vulnerabilities is sort of beside the point. It's a test of malware blocking. And, at least today, vulnerabilities are a much smaller issue for end users than straight-out malware, and especially for IE9. I think the test is a very reasonable one.
>>What about the lack of measurement of vulnerable and outdated browser plugins which could lead to a successful exploitation through a web based malware exploitation kit
But surely these would be blocked, at least in part, by the URL reputation system.
Discussion on:
Message 1 of 1
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



