Windows XP SP3 includes vulnerable Flash Player

Posted by Ankur Mittal 4 June, 2008

Microsoft Corp.’s Windows XP Service Pack 3 (SP3) ships with an out-of-date version of Adobe’s Flash Player that’s vulnerable to recently-spotted attacks, according to Microsoft’s support documentation. Windows XP SP3 includes Flash Player 9.0.115.0, a version released by Adobe Systems Inc. in December 2007. That version of Flash Player, however, was superseded by version 9.0.124.0 on April 8, nearly two weeks before Microsoft decided SP3 was done by giving it a Release To Manufacturing (RTM) label and sending it out for distribution.
The older version that shipped with XP SP3, however, harbors a bug that hackers have been exploiting since last week; that’s when security researchers, including those at Symantec Corp., reported what they at first thought was a zero-day vulnerability in the most current edition of Flash, 9.0.124.0. A few days later, however, Symantec retracted that claim, and said that only the older 9.0.115.0 was at risk.
Adobe has confirmed that version 9.0.115.0, included with XP SP3, is vulnerable to the ongoing attacks, which have originated from Chinese servers. Users have been attacked after visiting legitimate Web sites that had been hacked using now-common SQL-injection attacks. Users running XP SP3 can determine which version of Flash Player is installed by calling up this Adobe page in their browser. Adobe has recommended that all users update to version 9.0.124.0.
 

Source: ComputerWorld

If you're new here, you may want to subscribe to my RSS feed. Thanks for visiting!

Tags: Microsoft, Windows, Windows XP, windows xp service pack

Categories : Windows XP Tags : , , ,

Comments

No comments yet.


Leave a comment

(required)

(required)