Vulnerability announcement to exploit - time window
(from a posting by M S Hines to a mailing list)
"Information Security, July 2004, p 23 contains an article on the time the
world has to patch against the latest vulnerability (source: Foundstone).
The data shows the time between the announcement of a vulnerability or
release of a patch and a malware-bearing exploit being discovered in the
wild (an 'interesting' term - in the wild usually means 'attacking your
hosts').
1999 - 280.5 days
2000 - 104 days
2001 - 205 days
2002 - 88 days
2003 - 26 days
2004 - 10 days
"