Very old Flash versions put users at risk

Oct 28, 2015 16:54 GMT  ·  By

Adobe has been facing a lot of criticism lately due to a poor and slow patching mechanism used for its Flash Player application, which according to recent reports, still runs on over 90% of Internet-connected PCs.

Surprising or not, this 90% number is going to seem a dangerous figure when you couple it with a recent Secunia (now part of Flexera Software) report, which claims that 80% of all Flash installations are running an EOL version.

EOL stands for End Of Life and is a term used in computer software for applications to which its maker has stopped releasing updates and security patches. It basically means "really old" in geek speak.

Outside Flash, a lot of software is also left unpatched

While the report points out that users miserably fail when it comes to keeping their Flash Player up to date, there are also lots of other software products left without the latest updates.

Secunia says that users have around 76 applications from 27 vendors installed on their PCs, 32 of them (43%) being from Microsoft.

While Microsoft does a pretty good job at regularly patching its software applications every Tuesday, the other 26 software vendors tend to have different ways at looking at security bugs, which in turn has made a jumble of the end users’ overall PC security.

With 46% of all security vulnerabilities originating in non-Microsoft products, many infosec experts are left to ponder over the need of an OS-wide, standardized patching process that all applications can tap into just like with any other regular API.

While this is only a theory for now, reports like the ones coming from Secunia, only come to prove the need for better-standardized software update processes.  

Rank Program Market Share
Top 10 End-of-Life (EOL) Programs
1 Adobe Flash Player 18.x 80%
2 Microsoft XML Core Services (MSXML) 4.x 67%
3 Oracle Java JRE 1.7.x/7.x 35%
4 Google Chrome 44.x 35%
5 Google Chrome 43.x 24%
6 Mozilla Firefox 39.x 24%
7 Mozilla Firefox 40.x 21%
8 Adobe AIR 18.x 17%
9 Oracle Java JRE 1.6.x/6.x 16%
10 Adobe AIR 3.x 13%

Rank Program Users unpatched Market share Vulnerabilities
Top 10 Most Exposed Programs
1 Apple QuickTime 7.x 61% 55% 18
2 Apple iTunes 12.x 47% 40% 106
3 Adobe Reader X 10.x 66% 22% 96
4 Oracle Java JRE 1.8.x/8.x 36% 40% 81
5 Adobe Reader XI 11.x 23% 50% 96
6 VLC Media Player 2.x 41% 27% 6
7 Adobe Shockwave Player 12.x 47% 21% 4
8 Mozilla Firefox 38.x 72% 11% 69
9 Microsoft .NET Framework 3.x 6% 99% 24
10 Microsoft .NET Framework 4.x 6% 99% 27