You can’t celebrate stopping the robbers while the vault door is still wide open.
Ask a small or mid-sized business about its security posture and you’ll hear about the firewall, the endpoint protection, the password policy. What you almost never hear about is one of the most overlooked and most commonly exploited attack surfaces in the SMB space: common application vulnerabilities.
We’re talking about the everyday, often free applications sitting on nearly every machine in your organization: 7-Zip, Adobe Reader, FileZilla, Google Chrome, Firefox, Microsoft Edge, Java Runtime Environment, and many more. Even more concerning are the thousands of once wildly popular browser plugins that are now obsolete and unsupported, yet still installed on production computers. Adobe Flash Player alone has more than 1,084 published, publicly available vulnerabilities.
A great example of how Flash can be compromised is CVE-2018-15982: a zero-day memory corruption flaw used in widespread drive-by download attacks to gain full administrative access. All a user had to do was visit the wrong web page.
What We Always Find (Not Often, but Always)
ArcLight regularly performs vulnerability scanning, management, and remediation for clients of all sizes, and what we always find (not often, but ALWAYS) is zero attempt to patch common applications or browser plugins, and no effort to remove end-of-life apps and plugins from systems.
The most egregious case we’ve encountered was an organization with more than 5,000 endpoints carrying 120,000+ unpatched applications, including web browsers and the aforementioned Adobe Flash Player, on more than half of the computers we scanned. And here’s the uncomfortable part: this was not a negligent organization. Look at what they did have in place:
- An enterprise-grade, fully configured corporate firewall, managed and monitored by both the IT department and a third-party vendor
- Enterprise-grade endpoint security agents on every machine
- An enterprise-grade SIEM
- No local administrator rights for any user
- Complex passwords that expired every 45 days
- Monthly Windows patch management that kept most servers and all workstations current (a few EOL servers remained in service at leadership’s insistence)
Beyond that, they had VLAN segmentation, baseline hardening of Microsoft 365, and periodic reviews of systems, policies, and procedures. By most checklists, this was a mature security program. But nobody was monitoring or patching common applications or browser plugins, and nobody had removed the dead ones.
Shooting the Robbers on Their Way Out of the Bank
We looked at their EDR, and it was working overtime. Dozens of attacks were being blocked on endpoints every single week. Occasional lateral movement was being stopped. And every one of those blocks was hailed as proof of success: “We’re good at what we do! Our software blocks threats!”
What it actually said was this: “We left the bank vault open and shot the robbers as they were leaving the bank.”
Who knows if anyone got out without being shot? They were too busy celebrating the robbers who failed to escape to wonder about the ones who got away, or the ones still inside the bank.
Meet Susy
Susy is your favorite data entry specialist. She has a glowing personality, works hard all day, exceeds every expectation, and has a penchant for clicking on every email that hits her inbox. Her hobbies include knitting, dog walking, caffeine-free Sprite Zero, and scouring the web for obscure add-ons to load onto her self-hosted Minecraft server.
In her off time, Susy keeps up with work by logging in to Microsoft 365 Outlook from her home computer, so she’s ready to go the minute she arrives at the office. During COVID, Susy was given a VPN connection so she could work from home. Now that COVID is over, she no longer has a work computer at the house, so she simply loaded the VPN client onto her personal computer. She still connects to the office network to review data entry files for accuracy before she returns to work. Susy is a real go-getter!
Recently, Susy was asked to organize a list of medical records and break them down by age, condition, and other identifying criteria. Regrettably, there wasn’t enough time to finish before the office closed at 5:00 PM. But no worries: Susy uploaded the files to her personal Google Drive so she could keep working from home on her personal computer. Luckily, she can download the files straight back onto her work computer when she returns. Just in case, though, she’s also putting a copy on the well-worn USB drive she keeps on her keychain.
Can You Spot the Buffet?
Can you spot all the places where Susy didn’t just open the door to let the thief into the bank, but actually set out a buffet? Can you see how she didn’t merely hand over access, but hid the thief’s tracks through multiple layers of it? Can you see how well-meaning Susy is very likely the greatest threat to the company she works for?
Count them. A personal computer, the same one that clicks every link and side-loads unvetted Minecraft add-ons, connected to the corporate network over VPN. Corporate email running on an unmanaged home machine. Protected medical records uploaded to a personal Google Drive account. The same records copied onto an unencrypted USB drive that lives on a keychain. Not one of these will ever show up in a firewall log as an attack, because none of them is an attack. It’s just Susy, exceeding expectations.
The Takeaway
The tools most organizations invest in (firewalls, EDR, SIEM) absolutely matter. But they are the police that show up as the robbers are making their getaway, and your unpatched applications are an open vault. If your patch management program stops at Windows Updates, you are not patching most of your actual attack surface.
Start by inventorying every application and browser plugin in your environment. Patch the common apps as rigorously as you patch Windows. Remove end-of-life software entirely; there is no patch coming for Flash. And talk with your team about the Susys in your organization, not to punish the go-getters, but to give them safe, sanctioned ways to do the work they’re so eager to do.
ArcLight helps organizations of all sizes find and close these gaps through vulnerability scanning, management, and remediation. If you’re not sure what’s living unpatched on your endpoints, we can show you, before someone else finds out first.

Brian Largent
Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)




