Microsoft Works With Adobe To Patch Windows 8 Flash Flaws

Microsoft has teamed up with Adobe Systems to patch the vulnerabilities in Flash Player that affects Windows 8.

The move is a change in course, as Redmond is choosing to push out a fix before the operating system hits stores next month.

Embedded Flash

In Windows 8, Microsoft has opted to embed Flash Player in Internet Explorer 10 (IE 10). Last week, the company said publicly that it would wait until Windows 8 was generally available before patching Flash Player with the latest updates issued last month by Adobe.

However, in a statement 13 September, a Microsoft spokesperson told eWEEK that the company is working with Adobe to release an update for Flash in IE 10 that will be available shortly. Since Flash Player is embedded in IE 10, Microsoft will be responsible for patching it for Windows 8 users.

“Ultimately, our goal is to make sure the Flash Player in Windows 8 is always secure and up-to-date, and to align our release schedule as closely to Adobe’s as possible,” the spokesperson said in a statement.

Wolfgang Kandek, CTO at Qualys, said the decision to embed Flash Player into IE 10 is the right thing to do, noting that integrating Flash into IE and taking the responsibility for rolling out patches will improve end-user security. Hopefully, the decision will pave the way for other third-party programs to be patched through the Microsoft updater, he said.

“When we look at statistics from our BrowserCheck application we constantly see that 3rd party applications (i.e. Flash, Java, Reader) are slower in updating than Windows native application (i.e. Windows Media Player),” he said in an email. “We attribute that to the lack of automatic update mechanisms in some older applications, plus usability and integration issues with the multiple update mechanisms that a typical PC user has to deal with.”

Such flaws are often targeted by users of exploit kits such as Black Hole, which recently was updated by its creator to include new features designed to thwart efforts by security researchers.

Right Decision

Lamar Bailey, director of security research and development at nCircle, said shipping a product with known security flaws is bad practice, and requiring a patch installation immediately after installing a new OS is no better.

“Since Microsoft decided to follow the Google Chrome model of embedding Flash within browser, they’re tied to Adobe now for better or worse,” he said in an email. “Flash has been plagued with security issues for a long time, and embedding Flash means that IE10 end users will have to wait for Microsoft to patch Flash issues.”

“How this will work out in the long run is anyone’s guess,” he said. “Will Adobe release security information to Microsoft early enough get Flash patches to Windows 8 users at the same time they hit the rest of the market? Will Adobe delay patches for everyone to sync up with Microsoft?”

Are you a security expert? Try our quiz!

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

Australia Rejects Elon Musk Claim About Social Media Ban For Under-16s

Government minister flatly rejects Elon Musk's “unsurprising” allegation that Australian government seeks control of Internet…

17 mins ago

Northvolt Files For Bankruptcy Protection In US

Northvolt files for Chapter 11 bankruptcy protection in the United States, and CEO and co-founder…

2 hours ago

UK’s CMA Readies Cloud Sector “Behavioural” Remedies – Report

Targetting AWS, Microsoft? British competition regulator soon to announce “behavioural” remedies for cloud sector

17 hours ago

Former Policy Boss At X Nick Pickles, Joins Sam Altman Venture

Move to Elon Musk rival. Former senior executive at X joins Sam Altman's venture formerly…

20 hours ago

Bitcoin Rises Above $96,000 Amid Trump Optimism

Bitcoin price rises towards $100,000, amid investor optimism of friendlier US regulatory landscape under Donald…

21 hours ago

FTX Co-Founder Gary Wang Spared Prison

Judge Kaplan praises former FTX CTO Gary Wang for his co-operation against Sam Bankman-Fried during…

22 hours ago