<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>FGCenter - Latest Threats, Advisories, Reports and News</title>
<link>http://www.fortiguard.com/</link>
<language>en</language>
<copyright>Copyright 2010 Fortinet Inc. All Rights Reserved</copyright>
<pubDate>Thu, 02 Sep 2010 14:50:01 -0800</pubDate>
	<item>
		<title>Threat Landscape Report - August 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period July 21st - August 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />The top 10 attack attempts detected for this period follow, ranked by the number of valid attack cases reported. Valid attack cases are defined as threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">MS.Windows.Help.Center.Protocol.Malformed.Escape.Sequence</td><td>30.4</td><td><b>Critical</b></td><td><b>+3</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>24.6</td><td><b>Critical</b></td><td><b>+1</b></td>        </tr>	<tr>		<td>3</td><td class="left">MS.IE.Userdata.Behavior.Code.Execution</td><td>20.9</td><td><b>Critical</b></td><td>-1</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>10.0</td><td><b>Critical</b></td><td><b>+1</b></td>        </tr>	<tr>		<td>5</td><td class="left">FTP.USER.Command.Overflow</td><td>6.8</td><td>High</td><td><b>+3</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>6.5</td><td>High</td><td><b>+3</b></td>        </tr>	<tr>		<td>7</td><td class="left">Apache.Expect.Header.XSS</td><td>6.5</td><td>Medium</td><td>-1</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>4.6</td><td><b>Critical</b></td><td><b>+4</b></td>        </tr>	<tr>		<td>9</td><td class="left">Sasfis.Botnet</td><td>3.9</td><td>High</td><td><b>+2</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.Windows.LSASS.Buffer.Overflow</td><td>2.6</td><td>High</td><td><b>+7</b></td>        </tr></table><br /><br />  <table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0810/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0810/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0810/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0810/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 114 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 28 were reported to be actively exploited (24.6%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0810/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0810/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tbody><tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr><tr><td>1</td><td ]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_august_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_august_2010.html</guid>
		<pubDate>Mon, 30 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Adobe Shockwave Player Vulnerabilities</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs has discovered three vulnerabilities in Adobe Shockwave Player, which can lead to remote code execution and denial of service.<br><br><b>Impact:</b><br><br>Remote code execution and denial of service.<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of affected software, please refer to the Adobe Security Bulletin reference below.<br><br><b>Additional Information:</b><br><br>Two memory corruption vulnerabilities were discovered, each of which is highlighted below:<ul><li>Memory corruption in "DIRAPI.dll" (CVE-2010-2863)</li><li>Memory corruption in "IML32.dll" (CVE-2010-2864)</li></ul>One denial of service vulnerability was discovered: <ul><li>Denial of service in "DIRAPI.dll" (CVE-2010-2865)</li></ul><br>The vulnerabilities are triggered when opening a malformed ".dir" file which contain an overly long length value in a certain field. For both CVE-2010-2863 and CVE-2010-2864, remote code execution is possible through memory corruption and integer overflow. For CVE-2010-2865, a denial of service occurs when Internet Explorer stops responding.<br><br><b>Solutions:</b><br><ul><li>Users should apply the solution <a href="http://www.adobe.com/support/security/bulletins/apsb10-20.html">provided by Adobe</a>.</li></ul>FortiGuard Labs released the following signature to protect against this vulnerability:<ul><li>"Adobe.Shockwave.Player.Lrtx.Chunk.Code.Execution" (CVE-2010-2863)</li><li>"Adobe.Shockwave.Director.Lscm.Chunk.Code.Execution" (CVE-2010-2864)</li><li>"Adobe.Shockwave.Director.Lscm.Chunk.Code.DoS" (CVE-2010-2865)</li></ul><br><b>References:</b><br><ul><li>Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb10-20.html">APSB10-20</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2863">CVE-2010-2863</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2864">CVE-2010-2864</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2865">CVE-2010-2865</a></li>   </ul><br><b>Acknowledgment:</b><br><ul><li>Honggang Ren of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-41.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-41.html</guid>
		<pubDate>Thu, 26 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for August 24, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on August 24, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-20.html">APSB10-20</a></td><td>These vulnerabilities could allow an attacker to run malicious code on the affected system.</td><td align="center">Critical</td><td align="center">Shockwave Player</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2863">CVE-2010-2863</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2864">CVE-2010-2864</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2865">CVE-2010-2865</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2866">CVE-2010-2866</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2867">CVE-2010-2867</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2868">CVE-2010-2868</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2869">CVE-2010-2869</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2870">CVE-2010-2870</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2871">CVE-2010-2871</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2872">CVE-2010-2872</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2873">CVE-2010-2873</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2874">CVE-2010-2874</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2875">CVE-2010-2875</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2876">CVE-2010-2876</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2877">CVE-2010-2877</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2878">CVE-2010-2878</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2879">CVE-2010-2879</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2880">CVE-2010-2880</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2881">CVE-2010-2881</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2882">CVE-2010-2882</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities since August 19,2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2863">CVE-2010-2863</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.lrtx.chunk.code.execution<br>[previousname: fg-vd-10-016-adobe].html">Adobe.Shockwave.Player.Lrtx.Chunk.Code.Execution<br>[Previous Name: FG-VD-10-016-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2864">CVE-2010-2864</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.director.lscm.chunk.code.execution<br>[previousname: fg-vd-10-017-adobe].html">Adobe.Shockwave.Director.Lscm.Chunk.Code.Execution<br>[Previous Name: FG-VD-10-017-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2865">CVE-2010-2865</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.director.lscm.chunk.code.dos<br>[previousname: fg-vd-10-018-adobe].html">Adobe.Shockwave.Director.Lscm.Chunk.Code.DoS<br>[Previous Name: FG-VD-10-018-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2866">CVE-2010-2866</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.director.tsac.chunk.code.execution<br>[previousname: adobe.0day.24151].html">Adobe.Shockwave.Director.tSAC.Chunk.Code.Execution<br>[Previous Name: Adobe.0day.24151]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2867">CVE-2010-2867</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.director.rcsl.chunk.pointer.code.execution<br>[previousname: adobe.0day.24150].html">Adobe.Shockwave.Director.RcsL.Chunk.Pointer.Code.Execution<br>[Previous Name: Adobe.0day.24150]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2868">CVE-2010-2868</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.media.file.parsing.memory.corruption<br>[previousname: adobe.0day.24155].html">Adobe.Shockwave.Player.Dir.Media.File.Parsing.Memory.Corruption<br>[Previous Name: Adobe.0day.24155]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2869">CVE-2010-2869</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.media.file.parsing.memory.corruption<br>[previousname: adobe.0day.24155].html">Adobe.Shockwave.Player.Dir.Media.File.Parsing.Memory.Corruption<br>[Previous Name: Adobe.0day.24155]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2870">CVE-2010-2870</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.director.mmap.trusted.chunk.size.code.execution<br>[previousname: adobe.0day.24153].html">Adobe.Shockwave.Director.Mmap.Trusted.Chunk.Size.Code.Execution<br>[Previous Name: Adobe.0day.24153]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2871">CVE-2010-2871</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.director.josh.chunk.code.execution<br>[previousname: adobe.0day.24158].html">Adobe.Shockwave.Director.Josh.Chunk.Code.Execution<br>[Previous Name: Adobe.0day.24158]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2872">CVE-2010-2872</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.iml32.module.memory.corruption<br>[previousname: adobe.0day.24160].html">Adobe.Shockwave.Player.IML32.Module.Memory.Corruption<br>[Previous Name: Adobe.0day.24160]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2873">CVE-2010-2873</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dirapi.module.memory.corruption<br>[previousname: adobe.0day.24161].html">Adobe.Shockwave.Player.DIRAPI.Module.Memory.Corruption<br>[Previous Name: Adobe.0day.24161]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2874">CVE-2010-2874</a></td><td><a1 href="/encyclopedia/vulnerabilit]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-40.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-40.html</guid>
		<pubDate>Tue, 24 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for August 19, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on August 19, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-17.html">APSB10-17</a></td><td>Vulnerabilities that could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center">Adobe Reader, Adobe Acrobat</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2862">CVE-2010-2862</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1240">CVE-2010-1240</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities since August 13, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2862">CVE-2010-2862</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.font.parsing.integer.overflow.html">Adobe.Reader.Font.Parsing.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1240">CVE-2010-1240</a></td><td><a1 href="/encyclopedia/vulnerability/pdf.with.launch.action.html">PDF.With.Launch.Action</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Thursday, August 19 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />   <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for August 19, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-17.html">http://www.adobe.com/support/security/bulletins/apsb10-17.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-38.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-38.html</guid>
		<pubDate>Thu, 19 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers VideoLAN VLC ID3v2 Flags Denial Of Service Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs has discovered a vulnerability in VideoLAN VLC, which allows a remote attacker to cause a denial of service through a malformed media file.<br><br><b>Impact:</b><br><br>Denial Of Service<br><br><b>Risk:</b><br><br>Medium<br><br><b>Affected Software:</b><br><br>VideoLAN VLC 1.0.x to 1.1.2, please see the reference below.<br><br><b>Additional Information:</b><br><br>The VLC player crashes upon loading a media file containing specifically crafted ID3v2 tags. According to Fortinet's FortiGuard Labs investigations, execution of arbitrary code is however not possible.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"VideoLan.VLC.ID3v2.Flags.DoS" on August 19, 2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>VideoLAN  Security Advisory:<a href="http://www.videolan.org/security/sa1004.html">http://www.videolan.org/security/sa1004.html</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2937">CVE-2010-2937</a></li></ul><br><br><b>Acknowledgment:</b><br><br><ul><li>David Maciejak and Dylan Yin of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-39.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-39.html</guid>
		<pubDate>Thu, 19 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for August 10, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on August 10, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-16.html">APSB10-16</a></td><td>These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center">Adobe Flash Player, Adobe AIR</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0209">CVE-2010-0209</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2188">CVE-2010-2188</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2213">CVE-2010-2213</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2214">CVE-2010-2214</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2215">CVE-2010-2215</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2216">CVE-2010-2216</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities since June 11, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2188">CVE-2010-2188</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.localconnection.memory.corruption.html">Adobe.Flash.Player.LocalConnection.Memory.Corruption</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, August 10 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />   <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for August 10, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-16.html">http://www.adobe.com/support/security/bulletins/apsb10-16.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-37.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-37.html</guid>
		<pubDate>Tue, 10 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for August 10, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for August.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx">MS10-046</a></td><td>Vulnerability in Windows Shell Could Allow Remote Code Execution (2286198)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2568">CVE-2010-2568</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-049.mspx">MS10-049</a></td><td>Vulnerabilities in SChannel Could Allow Remote Code Execution (980436)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2566">CVE-2010-2566</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3555">CVE-2009-3555</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-051.mspx">MS10-051</a></td><td>Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (2079403)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2561">CVE-2010-2561</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-052.mspx">MS10-052</a></td><td>Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution (2115168)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1882">CVE-2010-1882</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-053.mspx">MS10-053</a></td><td>Cumulative Security Update for Internet Explorer (2183461)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Internet Explorer</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2557">CVE-2010-2557</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2560">CVE-2010-2560</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2556">CVE-2010-2556</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2558">CVE-2010-2558</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2559">CVE-2010-2559</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1258">CVE-2010-1258</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-054.mspx">MS10-054</a></td><td>Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2550">CVE-2010-2550</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2551">CVE-2010-2551</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2552">CVE-2010-2552</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-055.mspx">MS10-055</a></td><td>Vulnerability in Cinepak Codec Could Allow Remote Code Execution (982665)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2553">CVE-2010-2553</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-056.mspx">MS10-056</a></td><td>Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1900">CVE-2010-1900</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1901">CVE-2010-1901</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1902">CVE-2010-1902</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1903">CVE-2010-1903</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-060.mspx">MS10-060</a></td><td>Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution (2265906)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Microsoft .NET Framework, Microsoft Silverlight</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0019">CVE-2010-0019</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1898">CVE-2010-1898</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-047.mspx">MS10-047</a></td><td>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (981852)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1888">CVE-2010-1888</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1889">CVE-2010-1889</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-048.mspx">MS10-048</a></td><td>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (2160329)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1894">CVE-2010-1894</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1895">CVE-2010-1895</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1896">CVE-2010-1896</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1897">CVE-2010-1897</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-050.mspx">MS10-050</a></td><td>Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (981997)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2564">CVE-2010-2564</a><br>  </td></tr> 	<tr><td alig]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-36.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-36.html</guid>
		<pubDate>Tue, 10 Aug 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threat Landscape Report - July 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period June 21st - July 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />The top 10 attack attempts detected for this period follow, ranked by the number of valid attack cases reported. Valid attack cases are defined as threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Java.Deployment.Toolkit.Launch.Method.Access</td><td>28.9</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IE.Userdata.Behavior.Code.Execution</td><td>14.9</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>3</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>10.9</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.Windows.Help.Center.Protocol.Malformed.Escape.Sequence</td><td>8.7</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>	<tr>		<td>5</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>4.6</td><td><b>Critical</b></td><td><b>+4</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">Apache.Expect.Header.XSS</td><td>3.5</td><td>Medium</td><td>-</td>        </tr>	<tr>		<td>7</td><td class="left">MS.IE.Deleted.DOM.Object.Access.Memory.Corruption</td><td>3.2</td><td><b>Critical</b></td><td><b>+3</b></td>        </tr>        <tr class="odd">		<td>8</td><td class="left">FTP.USER.Command.Overflow</td><td>3.2</td><td>High</td><td>-1</td>        </tr>	<tr>		<td>9</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>3.1</td><td>High</td><td>-1</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.IE.Event.Invalid.Pointer.Memory.Corruption</td><td>2.7</td><td><b>Critical</b></td><td>-4</td>        </tr></table><br /><br />  <table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0710/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0710/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0710/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0710/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 91 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 31 were reported to be actively exploited (34.1%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0710/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0710/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_july_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_july_2010.html</guid>
		<pubDate>Thu, 29 Jul 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Microsoft Windows Shell Could Allow Remote Code Execution Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in Microsoft Windows Shell.<br><br><b>Impact:</b><br><br>Remote Code Execution<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of Microsoft Windows Shell versions affected, please see the references below.<br><br><b>Additional Information:</b><br><br>This vulnerability exists, when a user browse to a folder with specially crafted shortcut. It can also be exploited through removable drives.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"MS.Windows.Shell.LNK.Code.Execution" on July 21, 2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>Microsoft Security Advisory:<a href="http://www.microsoft.com/technet/security/advisory/2286198.mspx">http://www.microsoft.com/technet/security/advisory/2286198.mspx</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2568">CVE-2010-2568</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-35.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-35.html</guid>
		<pubDate>Mon, 19 Jul 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for July 13, 2010</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for July.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-042.mspx">MS10-042</a></td><td>Vulnerability in Help and SupportCenter Could Allow Remote Code Execution (2229593)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1885">CVE-2010-1885</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-043.mspx">MS10-043</a></td><td>Vulnerability in Canonical Display Driver Could Allow Remote Code Execution (2032276)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3678">CVE-2009-3678</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-044.mspx">MS10-044</a></td><td>Vulnerabilities in Microsoft Office Access ActiveX Controls Could Allow Remote Code Execution (982335)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0814">CVE-2010-0814</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1881">CVE-2010-1881</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-045.mspx">MS10-045</a></td><td>Vulnerability in Microsoft Office Outlook Could Allow Remote Code Execution (978212)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0266">CVE-2010-0266</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in July 13, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0266">CVE-2010-0266</a></td><td><a1 href="/encyclopedia/vulnerability/ms.outlook.smb.attachment.spoofing.html">MS.Outlook.SMB.Attachment.Spoofing</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0814">CVE-2010-0814</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.access.activex.controls.code.execution.html">MS.Office.Access.ActiveX.Controls.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1881">CVE-2010-1881</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.accwiz.dll.uninitialized.variable.code.execution.html">MS.Office.ACCWIZ.DLL.Uninitialized.Variable.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1885">CVE-2010-1885</a></td><td><a1 href="/encyclopedia/vulnerability/ms.windows.help.center.protocol.malformed.escape.sequence.html">MS.Windows.Help.Center.Protocol.Malformed.Escape.Sequence</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3678">CVE-2009-3678</a></td><td><a1 href="/encyclopedia/vulnerability/ms.canonical.display.code.execution.html">MS.Canonical.Display.Code.Execution</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, July 13 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for July 13, 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jul.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jul.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-34.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-34.html</guid>
		<pubDate>Tue, 13 Jul 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for June 29, 2010</title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on June 29, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-15.html">APSB10-15</a></td><td>These vulnerabilities, including CVE-2010-1297 referenced in Security Advisory APSA10-01, could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td>  <td align="center">Critical</td><td align="center">Adobe Reader and Acrobat</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1240">CVE-2010-1240</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1285">CVE-2010-1285</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1295">CVE-2010-1295</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1297">CVE-2010-1297</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2168">CVE-2010-2168</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2201">CVE-2010-2201</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2202">CVE-2010-2202</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2203">CVE-2010-2203</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2204">CVE-2010-2204</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2205">CVE-2010-2205</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2206">CVE-2010-2206</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2207">CVE-2010-2207</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2208">CVE-2010-2208</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2209">CVE-2010-2209</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2210">CVE-2010-2210</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2211">CVE-2010-2211</a><br><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2212">CVE-2010-2212</a><br> </td></tr> </table> <br /><br /> 		     <h2 class="title">Threat Remediation</h2><br />   <p>Fortinet has provided coverage on these Adobe vulnerabilities since June 24, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1240">CVE-2010-1240</a></td><td><a1 href="/encyclopedia/vulnerability/PDF.With.Launch.Action.html">PDF.With.Launch.Action</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1285">CVE-2010-1285</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Flash.Player.Authplay.DLL.SWF.Handling.Code.Execution.html">Adobe.Flash.Player.Authplay.DLL.SWF.Handling.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2168">CVE-2010-2168</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.PDF.File.Embeded.Stream.Code.Execution">Adobe.Reader.PDF.File.Embeded.Stream.Code.Execution<br>[previous name: Adobe.0day.23641]</a1></td></tr> 		<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2201">CVE-2010-2201</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.PDF.File.Invalid.Pointer.Code.Execution.html">Adobe.Reader.PDF.File.Invalid.Pointer.Code.Execution<br>[previous name: Adobe.0day.23642]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2202">CVE-2010-2202</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.PDF.3difr.x3d.Memory.Corruption.html">Adobe.PDF.3difr.x3d.Memory.Corruption<br>[previous name: Adobe.0day.23644]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2203">CVE-2010-2203</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.RichMedia.Memory.Corruption.html">Adobe.Reader.RichMedia.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2204">CVE-2010-2204</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.Acrobat.PDF.File.Memory.Corruption.html">Adobe.Reader.Acrobat.PDF.File.Memory.Corruption<br>[previous name: Adobe.0day.23650]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2207">CVE-2010-2207</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.Cooltype.Compressed.Stream.Code.Execution.html">Adobe.Reader.Cooltype.Compressed.Stream.Code.Execution<br>[previous name:  Adobe.0day.23647]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2208">CVE-2010-2208</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.Crafted.Oject.Code.Execution.html">Adobe.Reader.Crafted.Oject.Code.Execution<br>[previous name: Adobe.0day.23649]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2209">CVE-2010-2209</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.Reader.CoolType.DLL.PDF.Handling.Memory.Corruption.html">Adobe.Reader.CoolType.DLL.PDF.Handling.Memory.Corruption<br>[previous name: Adobe.0day.23643]</a1></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2210">CVE-2010-2210</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.PDF.Malformed.Stream.Memory.Corruption.html">Adobe.PDF.Malformed.Stream.Memory.Corruption<br>[previous name: Adobe.0day.23646]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2211">CVE-2010-2211</a></td><td><a1 href="/encyclopedia/vulnerability/Adobe.PDF.Malformed.ICCBased.Memory.Corruption.html">Adobe.PDF.Malformed.ICCBased.Memory.Corruption<br>[previous name: Adobe.0day.23640]</a1></td></tr> </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />     <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Wednesday, June 30	 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br /> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-33.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-33.html</guid>
		<pubDate>Tue, 29 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threat Landscape Report - June 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period May 21st - June 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />The top 10 attack attempts detected for this period follow, ranked by the number of valid attack cases reported. Valid attack cases are defined as threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Java.Deployment.Toolkit.Launch.Method.Access</td><td>60.2</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IE.Userdata.Behavior.Code.Execution</td><td>17.2</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>3</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>12.8</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">Gumblar.Botnet</td><td>6.7</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>5</td><td class="left">MS.IE.Event.Invalid.Pointer.Memory.Corruption</td><td>5.1</td><td><b>Critical</b></td><td><b>+13</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">Apache.Expect.Header.XSS</td><td>4.2</td><td>Medium</td><td><b>+1</b></td>        </tr>	<tr>		<td>7</td><td class="left">FTP.USER.Command.Overflow</td><td>3.7</td><td>High</td><td><b>+1</b></td>        </tr>        <tr class="odd">		<td>8</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>3.4</td><td>High</td><td>-2</td>        </tr>	<tr>		<td>9</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>3.3</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.IE.Deleted.DOM.Object.Access.Memory.Corruption</td><td>3.3</td><td><b>Critical</b></td><td><b>+4</b></td>        </tr></table><br /><br />  <table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0610/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0610/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0610/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0610/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 201 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 71 were reported to be actively exploited (35.3%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0610/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0610/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="lef]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_june_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_june_2010.html</guid>
		<pubDate>Mon, 28 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for June 10, 2010</title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on June 10, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-14.html">APSB10-14</a></td><td>Vulnerabilities that can be exploited to cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center">Adobe Flash Player</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4546">CVE-2008-4546</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3793">CVE-2009-3793</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1297">CVE-2010-1297</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2160">CVE-2010-2160</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2161">CVE-2010-2161</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2162">CVE-2010-2162</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2163">CVE-2010-2163</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2164">CVE-2010-2164</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2165">CVE-2010-2165</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2166">CVE-2010-2166</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2167">CVE-2010-2167</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2169">CVE-2010-2169</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2170">CVE-2010-2170</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2171">CVE-2010-2171</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2172">CVE-2010-2172</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2173">CVE-2010-2173</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2174">CVE-2010-2174</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2175">CVE-2010-2175</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2176">CVE-2010-2176</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2177">CVE-2010-2177</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2178">CVE-2010-2178</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2179">CVE-2010-2179</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2180">CVE-2010-2180</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2181">CVE-2010-2181</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2182">CVE-2010-2182</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2183">CVE-2010-2183</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2184">CVE-2010-2184</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2185">CVE-2010-2185</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2186">CVE-2010-2186</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2187">CVE-2010-2187</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2188">CVE-2010-2188</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2189">CVE-2010-2189</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities since June 09, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1297">CVE-2010-1297</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.authplay.dll.swf.handling.code.execution<br>[previous name: adobe.0day.23305].html">Adobe.Flash.Player.Authplay.DLL.SWF.Handling.Code.Execution <br>[Previous Name: Adobe.0day.23305]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2160">CVE-2010-2160</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.avm2.getouterscope.opcode.code.execution.html">Adobe.Flash.Player.AVM2.getouterscope.Opcode.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2161">CVE-2010-2161</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.out.of.bounds.memory.indexing.html">Adobe.Flash.Player.Out.Of.Bounds.Memory.Indexing</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2163">CVE-2010-2163</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.avm2.keyboardevent.memory.corruption<br>[previous name: fg-vd-10-019-adobe].html">Adobe.Flash.Player.AVM2.KeyboardEvent.Memory.Corruption <br>[Previous Name: FG-VD-10-019-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2164">CVE-2010-2164</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.use.after.free.memory.corruption.html">Adobe.Flash.Player.Use.After.Free.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2165">CVE-2010-2165</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.air.dll.memory.corruption.html">Adobe.Flash.Player.Air.DLL.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2166">CVE-2010-2166</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.avm2.actionscript.memory.corruption<br>[previous name: fg-vd-10-001-adobe].html">Adobe.Flash.Player.AVM2.ActionScript.Memory.Corruption <br>[Previous Name: FG-VD-10-001-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2167">CVE-2010-2167</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.embeded.image.memory.corruption.html">Adobe.Flash.Player.Embeded.Image.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2170">CVE-2010-2170</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.unspecified.module.memory.corruption.html">Adobe.Flash.Player.Unspecified.Module.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2171">CVE-2010-2171</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.p]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-32.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-32.html</guid>
		<pubDate>Fri, 11 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Adobe Flash Vulnerabilities</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs has discovered three memory corruption vulnerabilities in Adobe Flash, which allow a remote attacker to compromise a system through a malicious SWF file.<br><br><b>Impact:</b><br><br>Remote code execution.<br><br><b>Risk:</b><br><br>High<br><br><b>Affected Software:</b><br><br>For a list of affected software, please refer to the Adobe Security Bulletin reference below. Please note that other Adobe products (such as Reader / Acrobat) incorporate Flash, and may be vulnerable as well.<br><br><b>Additional Information:</b><br><br>Three memory corruption vulnerabilities were discovered in Adobe Flash, each of which is highlighted below:<ul><li>Memory corruption in "Flash10d.ocx" (CVE-2010-2166)</li><li>Memory corruption in "Flash10e.ocx" (CVE-2010-2163)</li><li>Memory corruption through VMWare Tools Service (CVE-2010-2189)</li></ul></ul><br>The vulnerabilities (CVE-2010-2166, CVE-2010-2163) are triggered when opening and rendering a SWF movie file. A remote attacker could craft a malicious SWF file which exploits either one of these vulnerabilities, allowing them to compromise a system. The vulnerability (CVE-2010-2189) is triggered through a special environment condition when running a flash movie under VMWare and VMWare Tools.<br><br><b>Solutions:</b><br><ul><li>Users should apply the solution <a href="http://www.adobe.com/support/security/bulletins/apsb10-14.html">provided by Adobe</a>.</li></ul>FortiGuard Labs released the following signature to protect against this vulnerability:<ul><li>"FG-VD-10-001-Adobe" (CVE-2010-2166)</li><li>"FG-VD-10-019-Adobe" (CVE-2010-2163)</li></ul><br><b>References:</b><br><ul><li>Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb10-14.html">APSB10-14</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2166">CVE-2010-2166</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2163">CVE-2010-2163</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-2189">CVE-2010-2189</a></li>   </ul><br><b>Acknowledgment:</b><br><ul><li>Bing Liu of Fortinet's FortiGuard Labs (CVE-2010-2166, CVE-2010-2163)</li><li>Haifei Li of Fortinet's FortiGuard Labs (CVE-2010-2189)</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-30.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-30.html</guid>
		<pubDate>Thu, 10 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Microsoft Windows Help and Support Center Could Allow Remote Code Execution Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in Microsoft Windows Help and Support Center.<br><br><b>Impact:</b><br><br>Remote Code Execution<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of Microsoft Windows Help and Support Center versions affected, please see the references below.<br><br><b>Additional Information:</b><br><br>This vulnerability could allow remote code execution if a user views a specially crafted Web page or clicks a specially crafted link.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"MS.Windows.Help.Center.Protocol.Malformed.Escape.Sequence" on June 11,2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>Microsoft Security Advisory:<a href="http://www.microsoft.com/technet/security/advisory/2219475.mspx">http://www.microsoft.com/technet/security/advisory/2219475.mspx</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1885">CVE-2010-1885</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-31.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-31.html</guid>
		<pubDate>Thu, 10 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Microsoft Excel Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs has discovered a memory corruption vulnerability in Microsoft Office Excel, which allows a remote attacker to compromise a system through a malicious document.<br><br><b>Impact:</b><br><br>Remote code execution.<br><br><b>Risk:</b><br><br>High<br><br><b>Affected Software:</b><br><br>For a list of affected software, please refer to the Microsoft Security Bulletin reference below.<br><br><b>Additional Information:</b><br><br>One memory corruption vulnerability was discovered in Microsoft Office Excel:<ul><li>Memory corruption in "excel.exe" (CVE-2010-0823) </li></ul></ul><br>The vulnerability is triggered when opening and rendering an Excel file. A remote attacker could craft a malicious document which exploits this vulnerability, allowing them to compromise a system.<br><br><b>Solutions:</b><br><br>FortiGuard Labs released the following signature to protect against this vulnerability:<ul><li> "FG-VD-09-030-Microsoft" (CVE-2010-0823)</li><li>Users should apply the solution <a href="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx">provided by Microsoft</a>.</li></ul><br><b>References:</b><br><ul><li>Microsoft Security Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-038.mspx">MS10-038</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0823">CVE-2010-0823</a></ul><br><b>Acknowledgment:</b><br><ul><li>Bing Liu of Fortinet's FortiGuard Labs </li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-28.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-28.html</guid>
		<pubDate>Tue, 08 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for June 08, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for June.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-033.mspx">MS10-033</a></td><td>Vulnerabilities in Media Decompression Could Allow Remote Code Execution (979902)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1879">CVE-2010-1879</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1880">CVE-2010-1880</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-034.mspx">MS10-034</a></td><td>Cumulative Security Update of ActiveX Kill Bits (980195)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0252">CVE-2010-0252</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0811">CVE-2010-0811</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-035.mspx">MS10-035</a></td><td>Cumulative Security Update for Internet Explorer (982381)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Internet Explorer</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1259">CVE-2010-1259</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1262">CVE-2010-1262</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0255">CVE-2010-0255</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1257">CVE-2010-1257</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1264">CVE-2010-1264</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-032.mspx">MS10-032</a></td><td>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Elevation of Privilege (979559)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0485">CVE-2010-0485</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0484">CVE-2010-0484</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1255">CVE-2010-1255</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-036.mspx">MS10-036</a></td><td>Vulnerability?in COM Validation in Microsoft Office Could Allow Remote Code Execution (983235)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1263">CVE-2010-1263</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-037.mspx">MS10-037</a></td><td>Vulnerability in the OpenType Compact Font Format (CFF)) Driver Could Allow Elevation of Privilege (980218)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0819">CVE-2010-0819</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-038.mspx">MS10-038</a></td><td>Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (2027452)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0822">CVE-2010-0822</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0824">CVE-2010-0824</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1245">CVE-2010-1245</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1246">CVE-2010-1246</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1247">CVE-2010-1247</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1248">CVE-2010-1248</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1249">CVE-2010-1249</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1250">CVE-2010-1250</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1253">CVE-2010-1253</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1254">CVE-2010-1254</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0821">CVE-2010-0821</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0823">CVE-2010-0823</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1251">CVE-2010-1251</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1252">CVE-2010-1252</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-039.mspx">MS10-039</a></td><td>Vulnerabilities in Microsoft SharePoint Could Allow Elevation of Privilege (2028554)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Office, Microsoft Server Software</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0817">CVE-2010-0817</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1257">CVE-2010-1257</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-040.mspx">MS10-040</a></td><td>Vulnerability in Internet Information Services Could Allow Remote Code Execution (982666)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1256">CVE-2010-1256</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-041.mspx">MS10-041</a></td><td>Vulnerability?in Microsoft .NET Framework Could Allow Tampering (981343)</td><td align="center">Important</td><td align="center">Tampering</td><td>Microsoft Windows, Microsoft .NET Framework</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0217">CVE-2009-0217</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities since Apr 01, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td a]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-29.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-29.html</guid>
		<pubDate>Tue, 08 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Adobe Flash Player, Adobe Reader and Adobe Acrobat Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in Adobe Products.<br><br><b>Impact:</b><br><br>System Compromise<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of Adobe Products' versions affected, please see the references below.<br><br><b>Additional Information:</b><br><br>This vulnerability could allow an attacker to take control of the affected system by leveraging a vulnerability in Flash Player or authplay.dll component in Adobe Reader and Acrobat.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"Adobe.0day.23305" on June 08,2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>Adobe Security Advisory:<a href="http://www.adobe.com/support/security/advisories/apsa10-01.html">http://www.adobe.com/support/security/advisories/apsa10-01.html</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1297">CVE-2010-1297</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-27.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-27.html</guid>
		<pubDate>Mon, 07 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threat Landscape Report - May 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period April 21st - May 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />The top 10 attack attempts detected for this period follow, ranked by the number of valid attack cases reported. Valid attack cases are defined as threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Java.Deployment.Toolkit.Launch.Method.Access</td><td>62.5</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IE.Userdata.Behavior.Code.Execution</td><td>16.3</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>3</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>12.5</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">Gumblar.Botnet</td><td>11.8</td><td><b>Critical</b></td><td>-3</td>        </tr>	<tr>		<td>5</td><td class="left">Sasfis.Botnet</td><td>4.2</td><td>High</td><td>-1</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>3.6</td><td>High</td><td>-</td>        </tr>	<tr>		<td>7</td><td class="left">Apache.Expect.Header.XSS</td><td>3.6</td><td>Medium</td><td>-</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">FTP.USER.Command.Overflow</td><td>3.5</td><td>High</td><td>-3</td>        </tr>	<tr>		<td>9</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>3.2</td><td><b>Critical</b></td><td>-1</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>1.8</td><td><b>Critical</b></td><td>-1</td>        </tr></table><br /><br />  <table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0510/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0510/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0510/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0510/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 102 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 33 were reported to be actively exploited (32.4%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0510/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0510/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/Pushdo.RD!tr.dldr</td><td>12.6</td><td><b>new</b></td>    ]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_may_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_may_2010.html</guid>
		<pubDate>Tue, 01 Jun 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for May 26, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on May 26, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-13.html">APSB10-13</a></td><td>Vulnerabilities that can be exploited by opening malicious .ASL, .ABR, or .GRD file.</td><td align="center">Critical</td><td align="center">Adobe Photoshop CS4</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1296">CVE-2010-1296</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in May 20, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1296">CVE-2010-1296</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.photoshop.style.layer.code.execution.html">Adobe.Photoshop.Style.Layer.Code.Execution</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Wednesday, May 26 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />   <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for May 26, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-13.html">http://www.adobe.com/support/security/bulletins/apsb10-13.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-26.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-26.html</guid>
		<pubDate>Wed, 26 May 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Investigates Microsoft Canonical Display Driver Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Investigates a Vulnerability in Microsoft Canonical Display Driver.<br><br><b>Impact:</b><br><br>DoS/Possible Code Execution<br><br><b>Risk:</b><br><br>High<br><br><b>Affected Software:</b><br><br>For a list of Microsoft Canonical Display Driver versions affected, please see the references below.<br><br><b>Additional Information:</b><br><br>This is a vulnerability being exploited that could cause the affected system to stop responding and automatically restart. The possibility of remote code execution can't be excluded.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>References:</b><br><br><ul><li>Microsoft Security Advisory:<a href="http://www.microsoft.com/technet/security/advisory/2028859.mspx">http://www.microsoft.com/technet/security/advisory/2028859.mspx</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-25.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-25.html</guid>
		<pubDate>Wed, 19 May 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Adobe Shockwave Player Vulnerabilities (APSB10-12)</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs has discovered seven vulnerabilities in Adobe Shockwave Player that could compromise the affected system.<br><br><b>Impact:</b><br><br>System Compromise<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of Adobe versions affected, please see the references below.<br><br><b>Additional Information:</b><br><ul><li>Memory Corruption occurs when Shockwave Player parses ".dir" media file that can lead to exploitation. (CVE-2010-1280,CVE-2010-1286,CVE-2010-1287,CVE-2010-1289,CVE-2010-1290,CVE-2010-1291).</li><li>Heap overflow that can lead to exploitation. (CVE-2010-1288).</li></ul><br>Vulnerabilities are being exploited to run malicious code on the affected system.<br><br><b>Solutions:</b><br><ul><li>Users should apply the solution <a href="http://www.adobe.com/support/security/bulletins/apsb10-12.html">provided by Adobe.</a></li><li>FortiGuard Labs released the following signatures to protect against these vulnerabilities<ul><li>"Adobe.Shockwave.Player.Dir.Invalid.Length.Code.Execution", previously released as "FG-VD-10-013-Adobe"  (CVE-2010-1280)</li><li>"Adobe.Shockwave.Player.Dir.File.DEMX.Tag.Memory.Corruption", previously released as "FG-VD-10-004-Adobe"  (CVE-2010-1286)</li><li>"Adobe.Shockwave.Player.Dir.File.Length.Field.Memory.Corruption", previously released as "_FG-VD-10-006-Adobe"  (CVE-2010-1287)</li><li>"Adobe.Shockwave.Player.Dir.File.Parsing.Heap.Exhaustion", previously released as "FG-VD-10-007-Adobe"  (CVE-2010-1288)</li><li>"Adobe.Shockwave.Player.Dir.File.Handling.Memory.Corruption", previously released as "FG-VD-10-008-Adobe"  (CVE-2010-1289)</li><li>"Adobe.Shockwave.Player.IML32.Dll.Memory.Corruption", previously released as "FG-VD-10-011-Adobe"  (CVE-2010-1290)</li><li>"Adobe.Shockwave.Player.Dir.File.Parsing.Access.Violation", previously released as "FG-VD-10-009-Adobe"  (CVE-2010-1291)</li></ul></li></ul><br></li></ul><br><b>References:</b><br><ul><li></a>Adobe Security Bulletin::<a href="http://www.adobe.com/support/security/bulletins/apsb10-12.html">http://www.adobe.com/support/security/bulletins/apsb10-12.html</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1280">CVE-2010-1280</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1286">CVE-2010-1286</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1287">CVE-2010-1287</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1288">CVE-2010-1288</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1289">CVE-2010-1289</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1290">CVE-2010-1290</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1291">CVE-2010-1291</a></li></ul><br><b>Acknowledgment:</b><br><ul><li>Honggang Ren of Fortinet's FortiGuard Labs (CVE-2010-1280,CVE-2010-1286,CVE-2010-1287,CVE-2010-1289,CVE-2010-1290,CVE-2010-1291,CVE-2010-1288).</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-24.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-24.html</guid>
		<pubDate>Wed, 12 May 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for May 11, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on May 11, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-11.html">APSB10-11</a></td><td>Vulnerabilities that could lead to cross-site scripting and information disclosure.</td><td align="center">Important</td><td align="center">ColdFusion 8.0, 8.0.1, 9.0 and earlier versions</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3467">CVE-2009-3467</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1293">CVE-2010-1293</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1294">CVE-2010-1294</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-12.html">APSB10-12</a></td><td>Vulnerabilities being exploited to run malicious code on the affected system.</td><td align="center">Critical</td><td align="center">Shockwave Player 11.5.6.606 and earlier versions</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0127">CVE-2010-0127</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0128">CVE-2010-0128</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0129">CVE-2010-0129</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0130">CVE-2010-0130</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0986">CVE-2010-0986</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0987">CVE-2010-0987</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1280">CVE-2010-1280</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1281">CVE-2010-1281</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1282">CVE-2010-1282</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1283">CVE-2010-1283</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1284">CVE-2010-1284</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1286">CVE-2010-1286</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1287">CVE-2010-1287</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1288">CVE-2010-1288</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1289">CVE-2010-1289</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1290">CVE-2010-1290</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1291">CVE-2010-1291</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1292">CVE-2010-1292</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in May 11, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1293">CVE-2010-1293</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.coldfusion.logintowizard.cfm.xss.html">Adobe.ColdFusion.logintowizard.cfm.XSS</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0127">CVE-2010-0127</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.boundary.error.html">Adobe.Shockwave.Player.Dir.File.Boundary.Error</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0128">CVE-2010-0128</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.signedness.error.html">Adobe.Shockwave.Player.Dir.File.Signedness.Error</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0129">CVE-2010-0129</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.integer.overflow.html">Adobe.Shockwave.Player.Dir.File.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0130">CVE-2010-0130</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.memory.corruption.html">Adobe.Shockwave.Player.Dir.File.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0986">CVE-2010-0986</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockware.player.parsing.dir.file.memory.corruption.html">Adobe.Shockware.Player.Parsing.Dir.File.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0987">CVE-2010-0987</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockware.player.parsing.dir.file.buffer.overflow.html">Adobe.Shockware.Player.Parsing.Dir.File.Buffer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1280">CVE-2010-1280</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.invalid.length.code.execution<br>[previousname: fg-vd-10-013-adobe].html">Adobe.Shockwave.Player.Dir.Invalid.Length.Code.Execution<br>[Previous Name: FG-VD-10-013-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1281">CVE-2010-1281</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.offset.underflow.memory.corruption.html">Adobe.Shockwave.Player.Offset.Underflow.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1282">CVE-2010-1282</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.atom.size.dos.html">Adobe.Shockwave.Player.Dir.File.ATOM.Size.DoS</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1283">CVE-2010-1283</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.3d.parsing.memory.corruption.html">Adobe.Shockwave.Player.3D.Parsing.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1284">CVE-2010-1284</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.invalid.value.code.execution.html">Adobe.Shockwave.Player.Dir.Invalid.Value.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1286">CVE-2010-1286</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.demx.tag.memory.corruption<br>[previousname: fg-vd-10-004-adobe].html">]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-23.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-23.html</guid>
		<pubDate>Tue, 11 May 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for May 11, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for May.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-030.mspx">MS10-030</a></td><td>Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution (978542)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0816">CVE-2010-0816</a><br>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-031.mspx">MS10-031</a></td><td>Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution (978213)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office, Microsoft Visual Basic for Applications</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0815">CVE-2010-0815</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in May 12, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0815">CVE-2010-0815</a></td><td><a1 href="/encyclopedia/vulnerability/ms.windows.vbe6.dll.stack.memory.corruption.html">MS.Windows.VBE6.DLL.Stack.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0816">CVE-2010-0816</a></td><td><a1 href="/encyclopedia/vulnerability/ms.windows.mail.client.integer.overflow.html">MS.Windows.Mail.Client.Integer.Overflow</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, May 11 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for May 11, 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-may.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-may.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-22.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-22.html</guid>
		<pubDate>Tue, 11 May 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for April 30, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on April 30, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-10.html">APSB10-10</a></td><td>A vulnerability being exploited by opening a malicious .TIFF file in Photoshop CS4.</td><td align="center">Critical</td><td align="center">Adobe Photoshop CS4 version 11.0.0</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1279">CVE-2010-1279</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in May 05, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1279">CVE-2010-1279</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.photoshop.cs4.tiff.file.processing.code.execution.html">Adobe.Photoshop.CS4.TIFF.File.Processing.Code.Execution</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Friday, April 30 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />   <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for April 30, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-10.html">http://www.adobe.com/support/security/bulletins/apsb10-10.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-21.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-21.html</guid>
		<pubDate>Tue, 04 May 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Microsoft SharePoint Elevation of Privilege Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in Microsoft SharePoint.<br><br><b>Impact:</b><br><br>Privilege Escalation<br><br><b>Risk:</b><br><br>Medium<br><br><b>Affected Software:</b><br><br>For a list of Microsoft SharePoint versions affected, please see the references below.<br><br><b>Additional Information:</b><br><br>It is a vulnerability that could allow an attacker to inject a script resulting in an elevation of privilege within the SharePoint site.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"MS.SharePoint.Server.Help.aspx.XSS" on May 03, 2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0817">CVE-2010-0817</a></li><li>Microsoft Security Advisory:<a href="http://www.microsoft.com/technet/security/advisory/983438.mspx">http://www.microsoft.com/technet/security/advisory/983438.mspx</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-20.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-20.html</guid>
		<pubDate>Fri, 30 Apr 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threat Landscape Report - April 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period March 21st - April 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />The top 10 attack attempts detected for this period follow, ranked by the number of valid attack cases reported. Valid attack cases are defined as threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Gumblar.Botnet</td><td>42.8</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IE.Userdata.Behavior.Code.Execution</td><td>22.2</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>3</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>21.5</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">Sasfis.Botnet</td><td>7.2</td><td>High</td><td><b>+1</b></td>        </tr>	<tr>		<td>5</td><td class="left">FTP.USER.Command.Overflow</td><td>5.9</td><td>High</td><td><b>+1</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>5.5</td><td>High</td><td><b>+1</b></td>        </tr>	<tr>		<td>7</td><td class="left">Apache.Expect.Header.XSS</td><td>5.3</td><td>Medium</td><td><b>+1</b></td>        </tr>        <tr class="odd">		<td>8</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>3.3</td><td><b>Critical</b></td><td><b>+1</b></td>        </tr>	<tr>		<td>9</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>3.1</td><td><b>Critical</b></td><td><b>+1</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">Crystal.Reports.Path.Traversal</td><td>3.0</td><td><b>Critical</b></td><td><b>new</b></td>        </tr></table><br /><br />  <table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0410/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0410/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0410/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0410/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 108 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 30 were reported to be actively exploited (27.8%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/roundup0410/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/roundup0410/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   w	<tr><td>1</td><td class="left">W32/FraudPack.fam!tr</td><td>28.7]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_april_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_april_2010.html</guid>
		<pubDate>Wed, 28 Apr 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for April 13, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on April 13, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">APSB10-09</a></td><td>Vulnerabilities that could cause the application to crash and could allow an attacker to control the compromised system.</td><td align="center">Critical</td><td align="center">Adobe Reader, Adobe Acrobat</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0190">CVE-2010-0190</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0191">CVE-2010-0191</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0192">CVE-2010-0192</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0193">CVE-2010-0193</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0194">CVE-2010-0194</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0195">CVE-2010-0195</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0196">CVE-2010-0196</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0197">CVE-2010-0197</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0198">CVE-2010-0198</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0199">CVE-2010-0199</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0201">CVE-2010-0201</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0202">CVE-2010-0202</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0203">CVE-2010-0203</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0204">CVE-2010-0204</a><br>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1241">CVE-2010-1241</a><br>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in April 13, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0192">CVE-2010-0192</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.embeded.font.memory.corruption<br>[previousname: adobe.0day.20812].html">Adobe.Reader.Embeded.Font.Memory.Corruption<br>[Previous Name: Adobe.0day.20812]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0194">CVE-2010-0194</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.linesetcontinuation.memory.corruption<br>[previousname: fg-vd-10-003-adobe].html">Adobe.Reader.LineSetContinuation.Memory.Corruption<br>[Previous Name: FG-VD-10-003-Adobe]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0195">CVE-2010-0195</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.font.parsing.code.execution<br>[previousname: adobe.0day.20803].html">Adobe.Reader.Font.Parsing.Code.Execution<br>[Previous Name: Adobe.0day.20803]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0196">CVE-2010-0196</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.u3d.clodmeshdeclaration.memory.corruption<br>[previousname: adobe.0day.20805].html">Adobe.Reader.U3D.CLODMeshDeclaration.Memory.Corruption<br>[Previous Name: Adobe.0day.20805]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0197">CVE-2010-0197</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.richmedia.memory.corruption<br>[previousname: adobe.0day.20807].html">Adobe.Reader.RichMedia.Memory.Corruption<br>[Previous Name: Adobe.0day.20807]</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1241">CVE-2010-1241</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.acrobat.pro.cff.encodings.handling.heap.overflow<br>[previousname: fg-vd-10-005-adobe].html">Adobe.Reader.Acrobat.Pro.CFF.Encodings.Handling.Heap.Overflow<br>[Previous Name: FG-VD-10-005-Adobe]</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, April 13 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />   <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for April 13, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">http://www.adobe.com/support/security/bulletins/apsb10-09.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-19.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-19.html</guid>
		<pubDate>Tue, 13 Apr 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Adobe Reader / Acrobat Vulnerabilities (APSB10-09)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs has discovered two memory corruption vulnerabilities in Adobe Reader / Acrobat, which allow a remote attacker to compromise a system through a malicious document.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> High.<br> <br> <b>Affected Software:</b><br> <br> For a list of affected software, please refer to the Adobe Security Bulletin reference below.<br><br> <b>Additional Information:</b><br> <br> Two memory corruption vulnerabilities were discovered in Adobe Reader / Acrobat, each of which is highlighted below:<ul><li>Memory corruption in "3difr.x3d". The vulnerable X3D component is a plugin used to display 3D material, which when present in a PDF document, can lead to exploitation (CVE-2010-0194).</li><li>Memory corruption through heap overflow in "CoolType.dll" (CVE-2010-1241).</li></ul>The vulnerabilities are triggered when opening and rendering a PDF document. A remote attacker could craft a malicious document which exploits either one of these vulnerabilities, allowing them to compromise a system.<br><br> <b>Solutions:</b><br> <ul><li>Users should apply the solution <a href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">provided by Adobe</a>.</li></ul>FortiGuard Labs released the following signatures to protect against these vulnerabilities<ul><li>"Adobe.Reader.DeviceRGB.Subtype.Stream.Memory.Corruption", previously released as "FG-VD-10-003-Adobe" (CVE-2010-0194).</li><li> "Adobe.Reader.Acrobat.Pro.CFF.Encodings.Handling.Heap.Overflow", previously released as "FG-VD-10-005-Adobe" (CVE-2010-1241).</li></ul><b>References:</b><br> <ul> <li> Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb10-09.html">http://www.adobe.com/support/security/bulletins/apsb10-09.html</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0194">CVE-2010-0194</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-1241">CVE-2010-1241</a></li></ul> <br><b>Acknowledgment:</b><ul><li>Bing Liu of Fortinet's FortiGuard Labs (CVE-2010-0194)</li><li>Haifei Li of Fortinet's FortiGuard Labs (CVE-2010-1241)</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-18.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-18.html</guid>
		<pubDate>Tue, 13 Apr 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Microsoft Visio Vulnerabilities (MS10-028)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs has discovered two memory corruption vulnerabilities in Microsoft Office Visio, which allow a remote attacker to compromise a system through a malicious document.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> High.<br> <br> <b>Affected Software:</b><br> <br> For a list of affected software, please refer to the Microsoft Security Bulletin reference below.<br><br> <b>Additional Information:</b><br> <br> Two memory corruption vulnerabilities were discovered in Microsoft Office Visio, each of which is highlighted below:<ul><li>Memory corruption in "vislib.dll" (CVE-2010-0254)</li><li>Memory corruption in "vislib.dll" (CVE-2010-0256)</li></ul>The vulnerabilities are triggered when opening and rendering a Visio file. A remote attacker could craft a malicious document which exploits either one of these vulnerabilities, allowing them to compromise a system.<br><br> <b>Solutions:</b><br> <ul><li>Users should apply the solution <a href="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx">provided by Microsoft</a>.</li></ul>FortiGuard Labs released the following signatures to protect against these vulnerabilities<ul><li>"MS.Visio.Attribute.Memory.Corruption", previously released as "FG-VD-09-006-Microsoft" (CVE-2010-0254).</li><li>"MS.Visio.objectID.Memory.Corruption", previously released as "FG-VD-09-005-Microsoft" (CVE-2010-0256).</li></ul><b>References:</b><br> <ul> <li> Microsoft Security Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-028.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0254">CVE-2010-0254</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0256">CVE-2010-0256</a></li></ul> <br><b>Acknowledgment:</b><ul><li>Bing Liu of Fortinet's FortiGuard Labs.</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-17.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-17.html</guid>
		<pubDate>Tue, 13 Apr 2010 00:00:00 -0800</pubDate>
	</item>
</channel>
</rss>
