Home » Privacy & Security

90% of you run an insecure version of flash

By George Ou 6 August 2009 3 Comments

Adobe Flash bugLast Friday, a new version of Adobe Flash came out which patched the most recent critical flaws in Flash Player.  Yet because the update process isn’t automatic, most of you (YES YOU) have not updated your Flash Player in your web browser.  The fact that Adobe makes the manual update process a pain to use and forces you to install yet another download manager and tries to get you to install yet another browser toolbar doesn’t help.  The end result is that most of your computers are vulnerable to websites that display malicious flash content.

How do I know most of you are not updated?  My visitor statistics for my blog tells me so.  In fact, nearly 90% of you have not upgraded yet to Flash Version 10.0.32.18 and close to 25% of you are running an even older version of flash.

Most people insecure on flash

Looking at the trend from last Friday when the update was first made available to today, it looks like the adoption rate is slow and it will take a long time before three quarters of you are updated and 25% of you will probably never be up to date.  And because more than 9 out of 10 computers in the world have Flash installed, it means that 80% of the world’s computer are vulnerable today and 20% of the world’s computers will always be vulnerable.  When we factor in vulnerable versions of Adobe PDF Reader, it’s even worse.

Day Flash Player r22 Flash player r32
Last Friday 72.24% 3.68%
This Wednesday 64.91% 10.37%
Change -7.33% +6.69%

So what can you do about this?  Check your Flash version here and make sure it’s running at least version 10.0.32.18 as of 7/31/2009.  While you’re at it, make sure you’re running the latest version of Adobe Reader as well.  Bear in mind that you have to actively opt out of any bloatware that Adobe tries to push on you.

3 Comments »

  • 90% of you run an insecure version of flash | Technology for Mortals said:

    [...] Read the rest at DigitalSociety.org Categories: Adobe, Security, Security news Tags: Comments (0) Trackbacks (0) Leave a comment Trackback [...]

  • captain said:

    “most of you (YES YOU) have not updated your Flash Player in your web browser.”

    I sure did. I don’t want Adobe’s updater to run on my computer but there is always a blogger or twelve to remind me to update this stuff. And I’m using Flashblock, too.

  • Jack said:

    I heartily recommend Secunia’s PSI

    This little app will warn when you need to update (third-party) software. And with the click of a button it sends you to the proper download page, or a description of the vulnerability.

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.