Saying that it doesn't test client-side vulnerabilities is sort of beside the point. It's a test of malware blocking. And, at least today, vulnerabilities are a much smaller issue for end users than straight-out malware, and especially for IE9. I think the test is a very reasonable one.
>>What about the lack of measurement of vulnerable and outdated browser plugins which could lead to a successful exploitation through a web based malware exploitation kit
But surely these would be blocked, at least in part, by the URL reputation system.
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



