Internet Explorer 10's bundled Flash leaves users exploitable

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,403
Early users of Windows 8's built-in Internet Explorer may find themselves at risk of exploitation via the Flash plugin, as the version included with Windows 8 is out of date. Adobe patched Flash on August 21 to resolve known security flaws, but the patch can't be applied to Internet Explorer 10.

Internet Explorer 10 bundles Adobe Flash, with Microsoft taking on responsibility for shipping updates to the integrated plugin. One repercussion of this arrangement is that Adobe's patches and autoupdate mechanism can't be used; they can update the standalone version used by Firefox, but not the embedded version in Internet Explorer. The same is true of Chrome; it includes an embedded version of Flash, and the only way to update that is with a Chrome update. Adobe's updater can't touch it.

There has been some chatter on Twitter about this issue since Adobe shipped its most recent patch. Ed Bott at ZDNet asked Microsoft about the issue, and was told:

We will update Flash in Windows 8 via Windows Update as needed. The current version of Flash in the Windows 8 RTM build does not have the latest fix, but we will have a security update coming through Windows Update in the GA timeframe.

"GA" means general availability; it refers to the October 26th date when Windows 8 will go on sale through retail channels. There is a contradiction implicit in this statement; Flash in Windows 8 needs an update now, so plainly Microsoft is not updating it "as needed."

Source




They should have made Adobe Flash Player for IE10 available from the Windows Store. Quite disappoint to say the least, but most would switch to their preferred browser, hopefully.
 

samit

Level 12
Verified
Nov 4, 2011
830
Only metro version of IE10 comes with inbuilt Adobe Flash Player....but for desktop version of IE10, Adobe Flash Player should be installed separately right!!!......correct me if I am wrong....
 

InternetChicken

New Member
Jul 16, 2012
519
Nice , Windows 8's built-in Internet Explorer , holes already, Microsoft lol ,
Why am I not surprised by this .
 

WinAndLinuxTutorials

Level 4
Verified
Honorary Member
Aug 23, 2011
2,291
samit said:
Only metro version of IE10 comes with inbuilt Adobe Flash Player....but for desktop version of IE10, Adobe Flash Player should be installed separately right!!!......correct me if I am wrong....

No, it wasnt allowing me to install it on the desktop version either.
Microsoft seems to be a security risk by itself. :p
 

HeffeD

Level 1
Feb 28, 2011
1,690
madyrocksin said:
New things will always have holes to exploit !!

It's not so much that its new, it's the fact that Microsoft doesn't see the need to update it that is concerning... :s
 

InternetChicken

New Member
Jul 16, 2012
519
HeffeD is right Microsoft as usual have their head in the clouds again,
and the best interests of windows user's at heart , again .....
 

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,403
I always forget about that. IE10 Metro has Enhanced Protection Mode enabled too, should that prevent anything?

samit said:
Only metro version of IE10 comes with inbuilt Adobe Flash Player.
 

DeadDrop

New Member
Aug 19, 2012
69
Why does everything come with flash these days? Flash in IE10 = so many holes like swiss cheese.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top