It appears that XP service pack 3 installs an older vulnerable version of the flash player - Microsoft Security Bulletin MS06-069

Vulnerabilities in Macromedia Flash Player from Adobe Could Allow Remote Code Execution (923789)

Published: November 14, 2006 | Updated: May 13, 2008

Version: 2.0

Summary
Who Should Read this Document: Customers who use Microsoft Windows

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: This bulletin is for customers using Macromedia Flash Player version 6 from Adobe. Customers that have followed the guidance in Adobe Security Bulletin APSB06-11, issued September 12, 2006, are not at risk from these vulnerabilities.

Link to article...

Filed under: ,