End of Life Adobe AIR - what to do from a security & compliance perspective
Hello. Our corporate Information Security department has identified several hundred Windows clients with versions of Adobe AIR that are end of life. Quite frankly, no one is familiar with Adobe AIR and if they're using it, it's only because of a dependency with a known application without realizing such a dependency exists.
We want to either remove the offending software or update it to a supported version. Pushing a version that's still within it's life cycle is out first choice as a balance between security and functionality but we're concerned with the latest version's ability to be backwards compatible. Is Adobe AIR similar to the Java RE in that upgrading it could result in breaking compatibility? Also, we notice almost all of our instances of outdated Adobe AIR is tied to a client that has either the Creative Suite or Photoshop elements installed. Do these applications rely on AIR? Do they just install it as part of a package?
