Launch Printer Friendly Page Security TechCenter > > Microsoft Security Advisory (2755801)

Microsoft Security Advisory (2755801)

Update for Vulnerabilities in Adobe Flash Player in Internet Explorer

Published: | Updated:

Version: 17.0

General Information

Executive Summary

Microsoft is announcing the availability of an update for Adobe Flash Player in Internet Explorer on all supported editions of Windows 8, Windows Server 2012, Windows RT, Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1. The update addresses the vulnerabilities in Adobe Flash Player by updating the affected Adobe Flash libraries contained within Internet Explorer 10 and Internet Explorer 11.

Mitigating Factors

Workarounds

Advisory Details 

Current Update

Microsoft recommends that customers apply the current update immediately using update management software, or by checking for updates using the Microsoft Update service. Since the update is cumulative, only the current update will be offered. Customers do not need to install previous updates as a prerequisite for installing the current update.

  • On December 10, 2013, Microsoft released an update 2907997 for Internet Explorer 10 on Windows 8, Windows Server 2012, and Windows RT, and for Internet Explorer 11 on Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2. The update addresses the vulnerabilities described in Adobe Security bulletin APSB13-28. For more information about this update, including download links, see Microsoft Knowledge Base Article 2907997.

    Notes 

    The update for Windows RT and Windows RT 8.1 is available via Windows Update
    The update is also available for Internet Explorer 11 Preview on Windows 8.1 Preview and Windows RT 8.1 Preview releases. The update is available via Windows Update.

Previous Updates

Affected Software

This advisory discusses the following software.

Operating SystemComponent
Affected Software
Windows 8 for 32-bit Systems Adobe Flash Player in Internet Explorer 10
Windows 8 for 64-bit Systems Adobe Flash Player in Internet Explorer 10
Windows Server 2012 Adobe Flash Player in Internet Explorer 10
Windows RTAdobe Flash Player in Internet Explorer 10
Windows 8.1 for 32-bit SystemsAdobe Flash Player in Internet Explorer 11
Windows 8.1 for 64-bit SystemsAdobe Flash Player in Internet Explorer 11
Windows Server 2012 R2Adobe Flash Player in Internet Explorer 11
Windows RT 8.1Adobe Flash Player in Internet Explorer 11

Non-Affected Software
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2 (Server Core installation)

Frequently Asked Questions

Other Information

Microsoft Active Protections Program (MAPP)

To improve security protections for customers, Microsoft provides vulnerability information to major security software providers in advance of each monthly security update release. Security software providers can then use this vulnerability information to provide updated protections to customers via their security software or devices, such as antivirus, network-based intrusion detection systems, or host-based intrusion prevention systems. To determine whether active protections are available from security software providers, please visit the active protections websites provided by program partners, listed in Microsoft Active Protections Program (MAPP) Partners.

Feedback

Support

  • Customers in the United States and Canada can receive technical support from Security Support. For more information about available support options, see Microsoft Help and Support.
  • International customers can receive support from their local Microsoft subsidiaries. For more information about how to contact Microsoft for international support issues, visit International Support.
  • Microsoft TechNet Security provides additional information about security in Microsoft products.

Disclaimer

The information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions

  • V1.0 (September 21, 2012): Advisory published.
  • V2.0 (October 8, 2012): Added the 2758994 update to the Current Update section.
  • V3.0 (October 23, 2012): Revised advisory to announce the availability of the 2758994 update for Windows RT.
  • V4.0 (November 6, 2012): Added the 2770041 update to the Current Update section.
  • V5.0 (December 11, 2012): Added the 2785605 update to the Current Update section.
  • V6.0 (January 8, 2013): Added the 2796096 update to the Current Update section.
  • V7.0 (February 7, 2013): Added the 2811522 update to the Current Update section.
  • V8.0 (February 12, 2013): Added the 2805940 update to the Current Update section.
  • V9.0 (February 26, 2013): Added the 2819372 update to the Current Update section.
  • V10.0 (March 12, 2013): Added the 2824670 update to the Current Update section.
  • V11.0 (April 9, 2013): Added the 2833510 update to the Current Update section.
  • V12.0 (May 14, 2013): Added the 2840613 update to the Current Update section.
  • V12.1 (May 14, 2013): Revised advisory to show the correct update and KB article numbers for update 2837385 released on May 14, 2013.
  • V13.0 (June 11, 2013): Added the 2847928 update to the Current Update section.
  • V14.0 (July 9, 2013): Added the 2857645 update to the Current Update section.
  • V15.0 (September 10, 2013): Added the 2880289 update to the Current Update section.
  • V16.0 (November 12, 2013): Added the 2898108 update to the Current Update section.
  • V17.0 (December 10, 2013): Added the 2907997 update to the Current Update section.