Adobe Flash again. InfoWorld Woody on Windows
[See the full post at: Microsoft re-issues critical Flash security patch MS16-064, retires KB 3157993-new version KB 3163207]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Microsoft re-issues critical Flash security patch MS16-064, retires KB 3157993-new version KB 3163207
Home » Forums » Newsletter and Homepage topics » Microsoft re-issues critical Flash security patch MS16-064, retires KB 3157993-new version KB 3163207
- This topic has 18 replies, 4 voices, and was last updated 8 years, 11 months ago.
Tags: KB 3157993 KB 3163207
AuthorTopicViewing 17 reply threadsAuthorReplies-
poohsticks
GuestMay 13, 2016 at 3:09 pm #42652Just wondering, does this patch from Microsoft do the same thing as Adobe’s patch?
Adobe’s new patch, Flash Player Version 21.0.0.242
https://get.adobe.com/flashplayer/?promoid=KLXMF -
Bliz
Guest -
Allan
Guest -
ch100
AskWoody_MVPMay 13, 2016 at 4:40 pm #42655Microsoft’s patch applies to Windows 8/8.1 and 10 which have Flash Player for IE (and Edge for Windows 10?) built in. For Firefox, the equivalent patch is from Adobe.
For Windows 7 and Vista, both patches, for IE and Firefox are from Adobe. One is Active X and the other one is the so-called NPAPI plug-in.
If you accept to limit your experience on the Internet to a certain extent for the purpose of reducing the attack surface, you could live without IE and Flash. Sooner or later you will find that this approach is too limiting, at least this is my experience.
In short, there are two distinct patches, one from Microsoft and the other from Adobe which should normally have the same version, although sometimes they are slightly out of sync. Chrome comes with its own Flash Player implementation and it is maintained by the browser.
Flash is an Adobe product and all the patches mentioned here are in fact originally developed by Adobe, but released under different brands to serve a specific purpose. -
ch100
AskWoody_MVPMay 13, 2016 at 4:48 pm #42656Woody says: ASPB16-15 covers 25 separately identified security holes (gotta love Flash)
Like Java RE, Flash Player is inherently insecure and sooner it disappears from the Internet, better for everyone. Until then, we can only patch newly discovered vulnerabilities, at the same time knowing that there is more to come, only not discovered or publicised yet.
-
EP
AskWoody_MVP -
PkCano
Guest -
RCPete
GuestMay 13, 2016 at 6:11 pm #42659The only reason I hadn’t killed Flash has been the need to do radar loops when storms hit, but the Weather Service radar page is now (mostly) duplicated by a function in a hazard map.
This covers the western region with full functions, but it’s spotty elsewhere in the country. I haven’t been able to find the equivalents for the central or eastern regions.
-
Bob(maybe)OrNot
GuestMay 13, 2016 at 6:39 pm #42660You can’t install the activex flash on windows 8+ (8.1,10) because it is part of the OS. Either install it via windows update, or microsoft’s standalone patch.
There is a dedicated version for firefox
Also there is a dedicated version for chome… but chrome’s flash is built-in so this version is for…? Actually I’d like to know the answer to that one.
Direct links (avoids prompts to install toolbars and mcafee-somethingorother):
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ax.exe Flash Player for Internet Explorer – ActiveX (Doesn’t apply to windows 8-10)
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player.exe Flash Player for Firefox – NPAPI
https://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_ppapi.exe Flash Player PPAPI -
ch100
AskWoody_MVP -
rc primak
GuestMay 14, 2016 at 6:36 am #42662What happened was that Flash Player had two very rapid security updates. The first, early May, went to Flash Player 21.0.0.140 from .132. The second one went to FP 21.0.0.142. Two separate updates. All browsers in all my OSes (Windows 10 and Linux) had the same pair of updates. Chrome for both OSes just finished the latest round on May 13th. Time to go to the MS Update Catalog again!
-
poohsticks
GuestMay 14, 2016 at 12:56 pm #42663Okay, If I have understood correctly, I have gleaned from the comments here:
A. The Windows-Update Flash update
– Is not for Windows 7 because in Windows 7, Flash is not embedded in I.E. and must be dealt with separately by the computer owner by getting updates for it directly from Adobe.
– Is for Windows versions higher than Windows 7, because in those versions of Windows, Flash is embedded in I.E. and Microsoft is managing all changes to it.B. The Adobe standalone update for Flash
– Is for Windows 7 computers
– Is not for Windows versions higher than Windows 7, because higher versions of Windows must rely on Microsoft’s Windows Updates to manage all changes to their computer’s Flash program.So I assume that, on my Windows 7 computer, I wouldn’t even have seen the Windows Update patches that Woody mentioned in the original blog post about this discussion, because they wouldn’t have applied to my system.
I expect that most people probably already know this information, but it is not mentioned in the InfoWorld article that this patch is only for Windows 8 and 10, and usually I think it is described which Windows versions the patches are for. I assumed the patches in question covered all Windows versions, since it wasn’t specified in the article.
=====
As to just getting rid of Flash and I.E., that isn’t desirable or possible at the present time for everyone to do…
I wrote under an earlier article on this site a day or two ago —
“Many, many people around the world still use IE and Adobe Flash. I use both. I have to use Flash for a few specific websites that I need to visit. Without Flash, the sites don’t work correctly. I have all the Flash options as locked down for safety as possible, I only turn it on once I’m at the site I where I need it to be on (and I don’t surf off of that site in the meantime), and I disable it in my IE tools when I’m not actively using it.” -
poohsticks
Guest -
poohsticks
Guest -
Noel Carboni
GuestMay 14, 2016 at 1:27 pm #42666>25 separately identified security holes (gotta love Flash)
Not that I have any love for Adobe Flash, but it’s not really special. Anything that runs in an executable on your system is inherently an attack surface. The run-time functionality is apparently just too complex to manage easily. At least Adobe is keeping on top of their add-on and delivering patches – not like Apple, who have abandoned their QuickTime Add-on.
Speaking of updates to things that run to bring in the glitz… What’s up with the Silverlight “update” – KB3126036 – that incessantly seems to show up in my WUShowHide tool on Windows 10?
http://Noel.ProDigitalSoftware.com/ForumPosts/Win10/10586/SilverlightUpdate0.png
http://Noel.ProDigitalSoftware.com/ForumPosts/Win10/10586/SilverlightUpdate1.png
http://Noel.ProDigitalSoftware.com/ForumPosts/Win10/10586/SilverlightUpdate2.png
Assuming this isn’t some kind of “stuck” update, it sure does seem like glitz delivery software can’t help but be riddled with vulnerabilities, doesn’t it?
But wait – while engineering things in the digital realm can be difficult, it’s not really a given that complex executable software MUST have vulnerabilities! Digital systems actually CAN achieve perfection. It just costs more and takes more time.
But blapping out code as quickly as possible, written by cheap, inexperienced programmers who may not follow best practices, foregoing system testing, and hoping for the best isn’t really the best strategy for keeping users safe, now is it?
Conclusion? Safety really isn’t the concern of companies supplying us with free software. Delivering the advertising to us in the most eye-catching manner is.
I choose not to play.
-Noel
-
Anonymous
GuestMay 14, 2016 at 2:50 pm #42667Try this site:
-
ch100
AskWoody_MVPMay 14, 2016 at 7:10 pm #42668This time is not Microsoft failing an update as it was suggested in some posts. It is Adobe’s product and Microsoft only provides a customised version for the Windows products which have Flash for Internet Explorer built-in.
Google is likely to do the same with their Flash plugin, only that their forced updates happen behind the scenes and nobody protests because their updates are a lot less intrusive for the end-user. -
ch100
AskWoody_MVPMay 14, 2016 at 11:31 pm #42669poohsticks, to clarify the B item, as I know that you are not a user of Windows 8/8.1/10. The same standalone from Adobe for Firefox (Opera and few other browsers) named NPAPI plugin applies to those versions as well. The Microsoft Update for Flash is only updating the Active X for IE in those versions.
Viewing 17 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Asking Again here (New User and Fast change only backups)
by
thymej
3 hours, 9 minutes ago -
How much I spent on the Mac mini
by
Will Fastie
3 hours, 15 minutes ago -
How to get rid of Copilot in Microsoft 365
by
Lance Whitney
3 hours, 7 minutes ago -
Spring cleanup — 2025
by
Deanna McElveen
9 hours, 1 minute ago -
Setting up Windows 11
by
Susan Bradley
2 hours, 3 minutes ago -
VLC Introduces Cutting-Edge AI Subtitling and Translation Capabilities
by
Alex5723
4 hours, 28 minutes ago -
Powershell version?
by
CWBillow
5 hours, 21 minutes ago -
SendTom Toys
by
CWBillow
1 minute ago -
Add shortcut to taskbar?
by
CWBillow
9 hours, 17 minutes ago -
Sycophancy in GPT-4o: What happened
by
Alex5723
1 day, 1 hour ago -
How can I install Skype on Windows 7?
by
Help
1 day ago -
Logitech MK850 Keyboard issues
by
Rush2112
7 hours, 17 minutes ago -
We live in a simulation
by
Alex5723
1 day, 15 hours ago -
Netplwiz not working
by
RetiredGeek
1 day, 2 hours ago -
Windows 11 24H2 is broadly available
by
Alex5723
2 days, 4 hours ago -
Microsoft is killing Authenticator
by
Alex5723
15 hours, 50 minutes ago -
Downloads folder location
by
CWBillow
2 days, 10 hours ago -
Remove a User from Login screen
by
CWBillow
1 day, 6 hours ago -
TikTok fined €530 million for sending European user data to China
by
Nibbled To Death By Ducks
2 days, 1 hour ago -
Microsoft Speech Recognition Service Error Code 1002
by
stanhutchings
2 days, 1 hour ago -
Is it a bug or is it expected?
by
Susan Bradley
3 hours, 55 minutes ago -
Image for Windows TBwinRE image not enough space on target location
by
bobolink
2 days ago -
Start menu jump lists for some apps might not work as expected on Windows 10
by
Susan Bradley
1 day ago -
Malicious Go Modules disk-wiping malware
by
Alex5723
2 days, 14 hours ago -
Multiple Partitions?
by
CWBillow
2 days, 15 hours ago -
World Passkey Day 2025
by
Alex5723
11 hours, 28 minutes ago -
Add serial device in Windows 11
by
Theodore Dawson
3 days, 23 hours ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
2 days ago -
Cached credentials is not a new bug
by
Susan Bradley
4 days, 4 hours ago -
Win11 24H2 Slow!
by
Bob Bible
4 hours, 31 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.