Windows XP SP3 includes vulnerable Flash Player
Microsoft's newest update bundles older version that's currently being exploited
Computerworld - Microsoft Corp.'s Windows XP Service Pack 3 (SP3) ships with an out-of-date version of Adobe's Flash Player that's vulnerable to recently spotted attacks, according to Microsoft's support documentation.
Windows XP SP3 includes Flash Player 188.8.131.52, a version released by Adobe Systems Inc. in December 2007. That version of Flash Player, however, was superseded by Version 184.108.40.206 on April 8, nearly two weeks before Microsoft decided SP3 was done by giving it a release to manufacturing (RTM) label and sending it out for distribution.
The older version that shipped with XP SP3, however, harbors a bug that hackers have been exploiting since last week; that's when security researchers, including those at Symantec Corp., reported what they at first thought was a zero-day vulnerability in the most current edition of Flash, 220.127.116.11. A few days later, however, Symantec retracted that claim, and said that only the older 18.104.22.168 was at risk.
Adobe has confirmed that Version 22.214.171.124, included with XP SP3, is vulnerable to the ongoing attacks, which have originated from Chinese servers. Users have been attacked after visiting legitimate Web sites that had been hacked using now-common SQL-injection attacks.
Microsoft noted that it bundled the outdated version of Flash Player with Windows XP in a document published on its support site; that document was last revised three weeks ago, on May 13. However, it has not advertised the fact or issued a security advisory recommending that users update Flash.
Computerworld has confirmed that PCs running XP SP3 use the obsolete 126.96.36.199 version of Flash.
Adobe patched Flash on April 8 to plug seven vulnerabilities, including one that was reported two weeks earlier after a researcher used it to claim a $5,000 prize in a hacking challenge.
Although Microsoft tagged Windows XP SP3 as RTM on April 21, it didn't release the service pack into general distribution via Windows Update until May 6. It has not yet triggered the update service to automatically download and install the service pack to users who have that option turned on; instead, users must explicitly go Windows Update and select SP3 from a list of offered updates.
Late Monday, Microsoft declined to answer questions about Flash, including why it wasn't able to add the newest version to XP SP3 and what advice it would give users.
Users running XP SP3 can determine which version of Flash Player is installed by calling up this Adobe page in their browser. Adobe has recommended that all users update to Version 188.8.131.52.
Read more about Security in Computerworld's Security Topic Center.
- The Truth About Cloud Security "Security" is the number one issue holding business leaders back from the cloud. But does the reality match the perception?
- Enable secure remote access to 3D data without sacrificing visual perfomance Design and manufacturing companies must adapt quickly to the demands of an increasingly global and competitive economy. To speed time to market for...
- Virtually Delivered High Performance 3D Graphics "A picture is worth a thousand words." That old phrase is as true today as it ever was. Pictures (i.e., those with heavy...
- Best Practices for Securing Hadoop Historically, Apache Hadoop has provided limited security capabilities. To protect sensitive data being stored and analyzed in Hadoop, security architects should use a...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!