Microsoft speeds up IE10 Flash patching, matches Google
Out-of-nowhere update for Flash likely triggered by upcoming $2 million 'Pwnium' hacking contest that Google kicks off Wednesday, says expert
Computerworld - Adobe today issued a surprise update for Flash Player that patched 25 critical vulnerabilities in the ubiquitous media software.
The California company urged Windows users to apply the update in the next 72 hours after rating the fix as "Priority 1" in its three-step system. That ranking indicates "vulnerabilities being targeted, or which have a higher risk of being targeted, by exploit(s) in the wild."
Google released an update for the Windows version of Chrome, which includes Flash Player, at 10 a.m. PT.
And although Microsoft dated the Internet Explorer 10 (IE10) for Windows 8 update as Oct. 5 on its download website, on Monday a spokeswoman for the Redmond, Wash. developer said that the date was incorrect. Like Google, Microsoft began pushing the IE10 update via Windows Update today at approximately 10 a.m. PT.
Of the 25 vulnerabilities, 14 were classified as buffer overflow bugs, and the remaining 11 were characterized as memory corruption flaws. All could "lead to code execution," Adobe said in its Monday security advisory.
Microsoft's swift patching of IE10 on Windows 8 today was in contrast to last month, when the company first said it would not fix Flash flaws until late October. After being blasted for its laissez-fair attitude, Microsoft backtracked, saying it would issue an update. It did so on Sept. 21, when a company executive promised closer coordination with Adobe.
Microsoft, not Adobe, is responsible for patching Flash Player in Windows 8 because the former has mimicked Google's Chrome by building the software into IE10.
While Windows 8 has not officially launched -- the new OS goes on sale Oct. 26 -- developers, IT professionals and many enterprises have had access to Windows 8 since mid-August.
Andrew Storms, director of security operations with nCircle Security, saw Google's hand in the unexpected Flash update.
"This idea that Adobe would coordinate with Microsoft makes me ask why couldn't they have waited until tomorrow?" Storms asked, noting that Oct. 9 is Microsoft's already-scheduled Patch Tuesday. "There are no exploits in the wild, according to Adobe. But then I got wind of this whole Pwnium thing, so the stars pretty much align."
- Russian credential theft shows why the password is dead
- Cybersecurity should be professionalized
- Feds declare big win over Cryptolocker ransomware
- Hackers hit more businesses through remote access accounts
- P.F. Chang's post-breach move to manual processing is telling
- Microsoft withholds monster IE update from Windows 8.1 dawdlers
- In baffling move, TrueCrypt open-source crypto project shuts down
- 'Oleg Pliss' hack makes for a perfect teachable IT moment
- Give IE the heave-ho until Microsoft patches zero-day
- Hackers find first post-retirement Windows XP-related vulnerability
- QA Automation: Reducing Test Execution While Improving Coverage A leading capital investment firm in the US was in need of a comprehensive, cost effective and flexible solution to reduce their existing...
- Tablet, Laptop, or Desktop - Form (Factor) Follows Function Desktops, laptops, Ultrabooks, tablets, convertibles, and all-in-ones; suddenly hardware decisions seem a lot more complicated. To take advantage of these benefits, the savviest...
- The IT handbook for Windows 7 and Windows 8 migrations A comprehensive guide for IT departments making the switch from legacy versions of Microsoft Windows to Windows 7 and Windows 8. To date,...
- 7 Reasons Why Windows 8 is the Future Touch, cloud, BYOD and IT consumerization dominate the mindshare of IT managers. Windows 8 enters the scene with a host of features that...
- API Management: The Key to Improving the Consumer Travel Experience Join PhoCusWright's Senior Technology Analyst, Norm Rose, as he shares his insights on how travel suppliers and intermediaries can improve industry data flow...
- Tips to Simplify Database Administration and Development Make your job easier while getting the most from the leading productivity tool for database professionals. Learn tips from Dell Software's Oracle® ACE,... All Operating Systems White Papers | Webcasts