<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>FGCenter - Latest Threats, Advisories, Reports and News</title>
<link>http://www.fortiguard.com/</link>
<language>en</language>
<copyright>Copyright 2010 Fortinet Inc. All Rights Reserved</copyright>
<pubDate>Tue, 16 Mar 2010 16:30:01 -0800</pubDate>
	<item>
		<title>Fortinet Protects Against Internet Explorer Could Allow Remote Code Execution Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in Internet Explorer.<br><br><b>Impact:</b><br><br>Remote Code Execution<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of Internet Explorer versions affected, please see the references below.<br><br><b>Additional Information:</b><br><br>The vulnerability exists due to an invalid pointer reference of a freed object that could cause remote code execution.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"MS.IE.Userdata.Behavior.Code.Execution" on March 11, 2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>Microsoft Security Advisory:<a href="http://www.microsoft.com/technet/security/advisory/981374.mspx">http://www.microsoft.com/technet/security/advisory/981374.mspx</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0806">CVE-2010-0806</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-14.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-14.html</guid>
		<pubDate>Tue, 09 Mar 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for March 09, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for March.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-016.mspx">MS10-016</a></td><td>Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0265">CVE-2010-0265</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-017.mspx">MS10-017</a></td><td>Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0257">CVE-2010-0257</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0260">CVE-2010-0260</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0261">CVE-2010-0261</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0263">CVE-2010-0263</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0264">CVE-2010-0264</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0258">CVE-2010-0258</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0262">CVE-2010-0262</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in March 09, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0257">CVE-2010-0257</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.entexu.memory.corruption.html">MS.Office.Excel.EntExU.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0260">CVE-2010-0260</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.mdxtuple.heap.overflow.html">MS.Office.Excel.Mdxtuple.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0261">CVE-2010-0261</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.mdxset.heap.overflow.html">MS.Office.Excel.Mdxset.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0263">CVE-2010-0263</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.xlsx.file.parsing.code.execution.html">MS.Office.Excel.XLSX.File.Parsing.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0264">CVE-2010-0264</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.dborparamqry.record.parsing.code.execution.html">MS.Office.Excel.DbOrParamQry.Record.Parsing.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0265">CVE-2010-0265</a></td><td><a1 href="/encyclopedia/vulnerability/ms.windows.movie.maker.producer.2003.heap.overflow.html">MS.Windows.Movie.Maker.Producer.2003.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0258">CVE-2010-0258</a></td><td><a1 href="/encyclopedia/vulnerability/ms.excel.brai.biff.record.code.execution.html">MS.Excel.BRAI.BIFF.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0262">CVE-2010-0262</a></td><td><a1 href="/encyclopedia/vulnerability/ms.excel.fngroupname.record.code.execution.html">MS.Excel.FnGroupName.Record.Code.Execution</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, March 09 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for March 09, 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-mar.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-13.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-13.html</guid>
		<pubDate>Tue, 09 Mar 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against VBScript Could Allow Remote Code Execution Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in VBScript.<br><br><b>Impact:</b><br><br>Remote Code Execution<br><br><b>Risk:</b><br><br>High<br><br><b>Affected Software:</b><br><br>For a list of softwares affected, please see the references below.<br><br><b>Additional Information:</b><br><br>The interaction of VBScript with Windows Help files when used with Internet Explorer could cause remote code execution. User interaction is required to a successful exploitation of this vulnerability.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"MS.IE.VBScript.Malicious.HLP.File.Command.Execution" on March 03,2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>Microsoft Security Bulletin:<a href="http://www.microsoft.com/technet/security/advisory/981169.mspx">http://www.microsoft.com/technet/security/advisory/981169.mspx</a></li><li>CVE ID:<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0483">CVE-2010-0483</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-12.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-12.html</guid>
		<pubDate>Mon, 01 Mar 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - February 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period January 21st - February 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />The top 10 attack attempts detected for this period follow, ranked by the number of valid attack cases reported. Valid attack cases are defined as threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Gumblar.Botnet</td><td>26.5</td><td><b>Critical</b></td><td>-</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>22.8</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>3</td><td class="left">MS.IE.Event.Invalid.Pointer.Memory.Corruption</td><td>15.3</td><td><b>Critical</b></td><td><b>+1</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">Waledac.Botnet</td><td>9.0</td><td><b>Critical</b></td><td>-1</td>        </tr>	<tr>		<td>5</td><td class="left">Sun.Java.HsbParser.GetSoundBank.Stack.Buffer.Overflow</td><td>8.0</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">FTP.USER.Command.Overflow</td><td>6.6</td><td>High</td><td><b>+1</b></td>        </tr>	<tr>		<td>7</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>6.0</td><td>High</td><td><b>+3</b></td>        </tr>        <tr class="odd">	<td>8</td><td class="left">Apache.Expect.Header.XSS</td><td>5.6</td><td>Medium</td><td>-</td>        </tr>	<tr>		<td>9</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>4.7</td><td><b>Critical</b></td><td><b>+3</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">RoundCube.Webmail.Pregreplace.Code.Execution</td><td>4.1</td><td>High</td><td><b>+3</b></td>        </tr></table><br /><br />  <table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0210/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0210/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0210/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0210/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 117 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 45 were reported to be actively exploited (38.5%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0210/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0210/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>  ]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_february_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_february_2010.html</guid>
		<pubDate>Fri, 26 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for February 16, 2010</title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on February 16, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">APSB10-07</a></td><td>A vulnerability that could subvert the domain sandbox.</td><td align="center">Critical</td><td align="center">Adobe Reader, Adobe Acrobat</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0188">CVE-2010-0188</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0186">CVE-2010-0186</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in February 16, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0188">CVE-2010-0188</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.reader.tiff.buffer.overflow.html">Adobe.Acrobat.Reader.Tiff.Buffer.Overflow</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, February 16 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />   <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for February 16, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-07.html">http://www.adobe.com/support/security/bulletins/apsb10-07.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-11.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-11.html</guid>
		<pubDate>Tue, 16 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for February 11, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on February 11, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Description</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-05.html">APSB10-05</a></td><td>A vulnerability that could result in disclosure of information when processing XML.</td><td align="center">Important</td><td align="center">Adobe BlazeDS, Adobe LiveCycle, Adobe LiveCycle Data Services, Adobe Flex Data Services,Adobe ColdFusion</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3960">CVE-2009-3960</a>  </td></tr> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-06.html">APSB10-06</a></td><td>A vulnerability that could subvert the domain sandbox and make unauthorized requests.</td><td align="center">Critical</td><td align="center">Adobe Flash Player, Adobe AIR</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0186">CVE-2010-0186</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0187">CVE-2010-0187</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in February 11, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3960">CVE-2009-3960</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.xml.entity.injection.html">Adobe.XML.Entity.Injection</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3960">CVE-2009-3960</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.xml.tag.injection.html">Adobe.XML.Tag.Injection</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0187">CVE-2010-0187</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.flash.dos.html">Adobe.Shockwave.Flash.DoS</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Thursday, February 11 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for February 11, 2010:</li>  <ul><li><a href="http://www.adobe.com/support/security/bulletins/apsb10-05.html">http://www.adobe.com/support/security/bulletins/apsb10-05.html</a></li>      <li><a href="http://www.adobe.com/support/security/bulletins/apsb10-06.html">http://www.adobe.com/support/security/bulletins/apsb10-06.html</a></li>  </ul> </ul>  ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-10.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-10.html</guid>
		<pubDate>Thu, 11 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for February 09, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for February.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-003.mspx">MS10-003</a></td><td>Vulnerability in Microsoft Office (MSO)) Could Allow Remote Code Execution (978214)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0243">CVE-2010-0243</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-004.mspx">MS10-004</a></td><td>Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0029">CVE-2010-0029</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0030">CVE-2010-0030</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0031">CVE-2010-0031</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0032">CVE-2010-0032</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0033">CVE-2010-0033</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0034">CVE-2010-0034</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-005.mspx">MS10-005</a></td><td>Vulnerability in Microsoft Paint Could Allow Remote Code Execution (978706)</td><td align="center">Moderate</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0028">CVE-2010-0028</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-006.mspx">MS10-006</a></td><td>Vulnerabilities in SMB Client Could Allow Remote Code Execution (978251)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0016">CVE-2010-0016</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0017">CVE-2010-0017</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-007.mspx">MS10-007</a></td><td>Vulnerability in Windows Shell Handler Could Allow Remote Code Execution (975713)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0027">CVE-2010-0027</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-008.mspx">MS10-008</a></td><td>Cumulative Security Update of ActiveX Kill Bits (978262)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-009.mspx">MS10-009</a></td><td>Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (974145)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0239">CVE-2010-0239</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0240">CVE-2010-0240</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0241">CVE-2010-0241</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0242">CVE-2010-0242</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-010.mspx">MS10-010</a></td><td>Vulnerability in Windows Server 2008 Hyper-V Could Allow Denial of Service (977894)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0026">CVE-2010-0026</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-011.mspx">MS10-011</a></td><td>Vulnerability in Windows Client/Server Run-time Subsystem Could Allow Elevation of Privilege (978037)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0023">CVE-2010-0023</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-012.mspx">MS10-012</a></td><td>Vulnerabilities in SMB Server Could Allow Remote Code Execution (971468)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0020">CVE-2010-0020</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0021">CVE-2010-0021</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0022">CVE-2010-0022</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0231">CVE-2010-0231</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-013.mspx">MS10-013</a></td><td>Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (977935)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0250">CVE-2010-0250</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-014.mspx">MS10-014</a></td><td>Vulnerability in Kerberos Could Allow Denial of Service (977290)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0035">CVE-2010-0035</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-015.mspx">MS10-015</a></td><td>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0232">CVE-2010-0232</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0233">CVE-2010-0233</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in February 09, 2010.</p>  <table class="threats"> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-09.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-09.html</guid>
		<pubDate>Tue, 09 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Oracle Privilege Escalation Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Labs Protects Against a Vulnerability in Oracle.<br><br><b>Impact:</b><br><br>Remote Command Execution<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br><br>For a list of Oracle versions affected, please see the BugTraq reference below.<br><br><b>Additional Information:</b><br><br>It is possible for a low privileged users to grant themselves arbitrary permissions through an overly permissive PL/SQL package.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><br><ul><li>FortiGuard Labs released the following signature which covers this specific vulnerability<ul><li>"Oracle.Database.JAVA.Packages.Command.Execution" on Feb. 10, 2010</li></ul></li></ul><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><br><ul><li>BugTraq ID:<a href="http://www.securityfocus.com/bid/38115">38115</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-08.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-08.html</guid>
		<pubDate>Mon, 08 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Microsoft Internet Explorer Vulnerability (980088)</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br> Fortinet's FortiGuard Labs Protects Against a Vulnerability in Microsoft Internet Explorer.<br><br> <b>Impact:</b><br> <br> Information Disclosure<br><br><b>Risk:</b><br> <br> High<br> <br><b>Affected Software:</b><br> <br> For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br><br><b>Additional Information:</b><br><br>The vulnerability exists due to content being forced to render incorrectly from local files in such a way that information can be exposed to malicious websites.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><ul><li>Follow the workarounds <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">provided by Microsoft</a> (980088).</li><li>FortiGuard Labs released a signature "MS.IE.Information.Disclosure" on Feb. 05,2010, which covers this specific vulnerability</li></ul><br><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><ul><li>Microsoft Advisory: <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">http://www.microsoft.com/technet/security/advisory/980088.mspx</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0255">CVE-2010-0255</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-07.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-07.html</guid>
		<pubDate>Thu, 04 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - January 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period December 21st, 2009 - January 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />Top 10 attack attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Gumblar.Botnet</td><td>31.3</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>24.3</td><td><b>Critical</b></td><td>-1</td>        </tr>	<tr>		<td>3</td><td class="left">Waledac.Botnet</td><td>7.6</td><td><b>Critical</b></td><td>-1</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.IE.Event.Invalid.Pointer.Memory.Corruption</td><td>7.4</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>	<tr>		<td>5</td><td class="left">Adobe.Products.SWF.Remote.Code.Execution</td><td>6.9</td><td><b>Critical</b></td><td><b>+6</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption</td><td>6.5</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>7</td><td class="left">FTP.USER.Command.Overflow</td><td>6.1</td><td>High</td><td>-3</td>        </tr>        <tr class="odd">	<td>8</td><td class="left">Apache.Expect.Header.XSS</td><td>6.0</td><td>Medium</td><td>-</td>        </tr>	<tr>		<td>9</td><td class="left">Adobe.Reader.Printf.Buffer.Overflow</td><td>5.8</td><td><b>Critical</b></td><td><b>+10</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>5.8</td><td>High</td><td>-7</td>        </tr></table><br /><br /><table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0110/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0110/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0110/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0110/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 150 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 34 were reported to be actively exploited (22.7%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0110/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0110/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_january_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_january_2010.html</guid>
		<pubDate>Wed, 27 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Microsoft Internet Explorer Vulnerability (MS10-002)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs has discovered a memory corruption vulnerability in Microsoft's Internet Explorer.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> Critical.<br> <br> <b>Affected Software:</b><br> <br> For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br><br> <b>Additional Information:</b><br> <br> In order to compromise a system / remotely execute code, an attacker would lure a user to a maliciously crafted website. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. <br><br> <b>Solutions:</b><br> <br> Since an attack scenario would require a user to visit a malicious website, it is recommended to have a layered security solution through webfiltering and intrusion prevention for mitigation.<ul> <li>Use the solution <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">provided by Microsoft</a> (MS10-002).</li><li>FortiGuard Labs released the signature "MS.IE.MergeAttributes.Remote.Code.Execution".</li><ul><li>Advanced zero-day protection has been available since September 3, 2009.</li></ul></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.<br> <br> Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br ><br> <b>References:</b><br> <ul> <li> Microsoft Security Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0247">CVE-2010-0247</a></li></ul> <br><b>Acknowledgment:</b><ul><li>Haifei Li of Fortinet's FortiGuard Labs.</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-05.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-05.html</guid>
		<pubDate>Thu, 21 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for January 21, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for January 21, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx">MS10-002</a></td><td>Cumulative Security Update for Internet Explorer (978207)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4074">CVE-2009-4074</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0027">CVE-2010-0027</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0244">CVE-2010-0244</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0245">CVE-2010-0245</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0246">CVE-2010-0246</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0247">CVE-2010-0247</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0248">CVE-2010-0248</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0249">CVE-2010-0249</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in January 21, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0244">CVE-2010-0244</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.object.handler.memory.corruption.html">MS.IE.Object.Handler.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0245">CVE-2010-0245</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.dom.operation.memory.corruption.html">MS.IE.DOM.Operation.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0246">CVE-2010-0246</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie8.uninitialized.memory.corruption.html">MS.IE8.Uninitialized.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0247">CVE-2010-0247</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.mergeattributes.remote.code.execution.html">MS.IE.MergeAttributes.Remote.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0248">CVE-2010-0248</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.html.removed.table.reference.memory.corruption.html">MS.IE.HTML.Removed.Table.Reference.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0249">CVE-2010-0249</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.event.invalid.pointer.memory.corruption.html">MS.IE.Event.Invalid.Pointer.Memory.Corruption</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Thursday, January 21 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for January 21, 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-06.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-06.html</guid>
		<pubDate>Thu, 21 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for January 19, 2010</title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on January 19, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-03.html">apsb10-03</a></td><td>Vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system.</td><td align="center">Critical</td><td align="center">Shockwave Player 11.5.2.602 and earlier versions for Windows and Macintosh</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4002">CVE-2009-4002</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4003">CVE-2009-4003</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in January 19, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4002">CVE-2009-4002</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.parsing.heap.overflow.html">Adobe.Shockwave.Player.Dir.File.Parsing.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4003">CVE-2009-4003</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.parsing.integer.overflow.html">Adobe.Shockwave.Player.Dir.File.Parsing.Integer.Overflow</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Thursday, January 19 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for January 19, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-03.html">http://www.adobe.com/support/security/bulletins/apsb10-03.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-04.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-04.html</guid>
		<pubDate>Tue, 19 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Vulnerability in Internet Explorer Could Allow Remote Code Execution (979352)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs protects against a remote code execution vulnerability in Internet Explorer.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> Critical.<br> <br> <b>Affected Software:</b><br> <br> For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br><br> <b>Additional Information:</b><br> <br> The vulnerability exists as an invalid pointer reference within Internet Explorer. It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution. In order to compromise a system / remotely execute code, an attacker would lure a user to a maliciously crafted website.<br><br> <b>Solutions:</b><br> <br> Since an attack scenario would require a user to visit a malicious website, it is recommended to have a layered security solution through webfiltering and intrusion prevention for mitigation.<br ><br ><b>Updated:</b> January 21, 2009<ul> <li> Use the solution <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">provided by Microsoft</a>.</li><li>FortiGuard Labs released the signature "MS.IE.Event.Invalid.Pointer.Memory.Corruption" (CVE-2010-0249).</li> </ul> FortiGuard Labs continues to monitor attacks against this vulnerability.<br> <br> Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br ><br> <b>References:</b><br> <ul> <li>Microsoft Security Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a></li><li> Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">http://www.microsoft.com/technet/security/advisory/979352.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0249">CVE-2010-0249</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-03.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-03.html</guid>
		<pubDate>Mon, 18 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for January 12, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on January 12, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">apsb10-02</a></td><td>Vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center">Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX,Adobe Acrobat 9.2 and earlier versions for Windows and Macintosh</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3953">CVE-2009-3953</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3954">CVE-2009-3954</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3955">CVE-2009-3955</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3956">CVE-2009-3956</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3957">CVE-2009-3957</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3958">CVE-2009-3958</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3959">CVE-2009-3959</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4324">CVE-2009-4324</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in January 12, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3953">CVE-2009-3953</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.u3d.clod.mesh.declaration.array.buffer.overflow.html">Adobe.U3D.CLOD.Mesh.Declaration.Array.Buffer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3955">CVE-2009-3955</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.jpxdecode.jp2c.stream.memory.corruption.html">Adobe.Reader.JpxDecode.Jp2c.Stream.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3956">CVE-2009-3956</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.fdf.javascript.execution.html">Adobe.Reader.FDF.Javascript.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3957">CVE-2009-3957</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.pdf.colors.code.execution.html">Adobe.PDF.Colors.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3958">CVE-2009-3958</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.get.atlcom.activex.control.access.html">Adobe.Get.Atlcom.ActiveX.Control.Access</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3959">CVE-2009-3959</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.reader.u3d.content.integer.overflow.html">Adobe.Acrobat.Reader.U3D.Content.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4324">CVE-2009-4324</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.javascript.newplayer.method.code.execution.html">Adobe.Reader.Javascript.newplayer.Method.Code.Execution</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, January 12 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for January 12, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">http://www.adobe.com/support/security/bulletins/apsb10-02.html</a></li></ul>  ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-02.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-02.html</guid>
		<pubDate>Tue, 12 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for January 2010</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for January.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx">MS10-001</a></td><td>Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0018">CVE-2010-0018</a>  </td></tr>  </table> <br /><br />   <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, January 12 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for January 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-01.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-01.html</guid>
		<pubDate>Tue, 12 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - December 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period November 21st - December 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />Top 10 attack attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>55.6</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">Waledac.Botnet</td><td>8.2</td><td><b>Critical</b></td>        </tr>	<tr>		<td>3</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>6.1</td><td>High</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">FTP.USER.Command.Overflow</td><td>4.6</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">MS.Windows.LSASS.Buffer.Overflow</td><td>4.5</td><td>High</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption</td><td>3.7</td><td><b>Critical</b></td>        </tr>	<tr>		<td>7</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>3.1</td><td><b>Critical</b></td>        </tr>        <tr class="odd">	<td>8</td><td class="left">Apache.Expect.Header.XSS</td><td>2.5</td><td>Medium</td>        </tr>	<tr>		<td>9</td><td class="left">Apache.MyFaces.Tomahawk.JSF.Framework.XSS</td><td>2.4</td><td>Medium</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">FTP.Command.REST.Overflow</td><td>2.3</td><td>High</td>        </tr></table><br /><br /><table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1209/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1209/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1209/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1209/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 157 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 46 were reported to be actively exploited (29.3%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1209/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1209/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/PackBredolab.C!tr</td><td>66.5</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">JS/PackRedir.A!tr.dldr</td><td>6.8</td><td><b>+17</b></td>        </tr>	<tr><td>3</td><td class="left">JS/Feebs.A@mm</td><td>2.2</td><td><b>+14</b></td>        </tr>        <tr class="odd"><td]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_december_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_december_2009.html</guid>
		<pubDate>Thu, 24 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for December 18, 2009</title>
		<description>
		<![CDATA[The table below lists the Adobe vulnerabilities for December.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="15%"> </th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb09-18.html">apsb09-18</a></td><td>Vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system.</td><td align="center">Critical</td><td align="center"></td><td>Flash Media Server 3.5.2 and earlier versions</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3791">CVE-2009-3791</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3792">CVE-2009-3792</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in December 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3791">CVE-2009-3791</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.media.server.resource.exhaustion.dos.html">Adobe.Flash.Media.Server.Resource.Exhaustion.DoS</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3792">CVE-2009-3792</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.media.server.directory.traversal.html">Adobe.Flash.Media.Server.Directory.Traversal</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Friday, December 18 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for December 2009: <a href="http://www.adobe.com/support/security/bulletins/apsb09-18.html">http://www.adobe.com/support/security/bulletins/apsb09-18.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-49.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-49.html</guid>
		<pubDate>Fri, 18 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Cisco WebEx WRF Player Vulnerabilities</title>
		<description>
		<![CDATA[<strong>Summary:</strong><p />Multiple memory corruption vulnerabilities exist in Cisco WebEx WRF Player which allow a remote attacker to compromise a vulnerable system.<p /><strong>Impact:</strong><p />Remote code execution / Denial of service.<p /><strong>Risk:</strong><p /> <ul><li> Critical</li></ul><p /><strong>Affected Software:</strong><p /> <ul><li> Cisco WebEx WRF Player 3.0 or earlier versions on Linux,Microsoft Windows and Mac OS X</li></ul><p /><strong>Additional Information:</strong><p />Six vulnerabilities were discovered in Cisco WebEx WRF Player, each of which is highlighted below:<p /> <ul><li> FG-VD-09-008: Cisco WebEx WRF Player Denial Of Service in "atrpui.dll" (CVE-2009-2880)</li> <li> FG-VD-09-010: Cisco WebEx WRF Player Heap Overflow in "atas32.dll" (CVE-2009-2879)</li> <li> FG-VD-09-012: Cisco WebEx WRF Player Heap Overflow in "atas32.dll" (CVE-2009-2876)</li> <li> FG-VD-09-013: Cisco WebEx WRF Player Heap Overflow in "atas32.dll" (CVE-2009-2878)</li> <li> FG-VD-09-014: Cisco WebEx WRF Player Stack Overflow in "ataudio.dll" (CVE-2009-2877)</li> <li> FG-VD-09-016: Cisco WebEx WRF Player Denial of Service in "atas32.dll" (CVE-2009-2875)</li></ul><p /><strong>Solutions:</strong><p />Use the <a href="http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml">solution provided by Cisco:</a>    <ul><li> FG-VD-09-008: fixed in WebEx releases T26 and T27</li> <li> FG-VD-09-010: fixed in WebEx releases T26SP49EP32 and T27SP10</li> <li> FG-VD-09-012: fixed in WebEx releases T26SP49EP32 and T27SP10</li> <li> FG-VD-09-013: fixed in WebEx releases T26SP49EP32 and T27SP10</li> <li> FG-VD-09-014: fixed in WebEx releases T26LSp49EP32 and T27SP10</li> <li> FG-VD-09-016: fixed in WebEx release T26SP49EP</li></ul>          <p /> FortiGuard Labs released the following signatures to protect against these vulnerabilities <ul><li> "Cisco.WebEx.Player.atas32.Heap.Overflow" (CVE-2009-2879, CVE-2009-2876, CVE-2009-2878)</li> <li> "Cisco.WebEx.Player.ataudio.Buffer.Overflow" (CVE-2009-2877)</li> <li> "Cisco.WebEx.Player.atrpui.DoS" (CVE-2009-2880)</li> <li> "Cisco.WebEx.Player.atas32.DoS" (CVE-2009-2875)</li></ul><p /><p /><p />Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against these memory corruption vulnerabilities. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by Fortinet's FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<p /><strong>References:</strong><p /> <ul><li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2880">CVE-2009-2880</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2879">CVE-2009-2879</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2876">CVE-2009-2876</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2878">CVE-2009-2878</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2877">CVE-2009-2877</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2875">CVE-2009-2875</a></li> <li> Cisco Security Advisory: <a href="http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml">http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml</a></li></ul><p /><p /><strong>Acknowledgment:</strong><p /> <ul><li>  Zhenhua Liu and XiaoPeng Zhang of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-48.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-48.html</guid>
		<pubDate>Wed, 16 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Reader / Acrobat Remote Code Execution Vulnerability (APSA09-07)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs investigates a vulnerability in Adobe Acrobat / Adobe Reader that leads to remote code execution.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> Critical.<br> <br> <b>Affected Software:</b><br> <br> For a list of product versions affected, please see the Adobe Security Advisory reference below.<br><br> <b>Additional Information:</b><br> <br> Attacks have been spotted in the wild which exploit this vulnerability through a maliciously crafted PDF file using Javascript functions. When the document is opened, further malicious components are typically downloaded for execution. FortiGuard Labs continues to monitor attacks against this vulnerability.<br> <br> <b>Solutions:</b><br> <br> <ul> <li> Use the solution provided <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html" id="uk15" title="suggested by Adobe">by Adobe</a> (APSA09-07).<br> </li> <li> FortiGuard Labs released the signature "Adobe.Reader.Javascript.newplayer.Method.Code.Execution" (CVE-2009-4324).</li> </ul> <br> <br> Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by Fortinet's FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br> <br> <b>References:</b><br> <ul> <li> Adobe Security Advisory: <a title="http://www.adobe.com/support/security/advisories/apsa09-07.html" href="http://www.adobe.com/support/security/advisories/apsa09-07.html" id="hqkx">http://www.adobe.com/support/security/advisories/apsa09-07.html</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3244">CVE-2009-4324</a> </li> </ul> <br> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-47.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-47.html</guid>
		<pubDate>Tue, 15 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for December 08, 2009 </title>
		<description>
		<![CDATA[The table below lists the Adobe vulnerabilities for December.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="15%"> </th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">APSB09-19</a></td><td>Vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center"> </td><td>Adobe Flash Player 10.0.32.18 and earlier versions,Adobe AIR 1.5.2 and earlier versions</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3794">CVE-2009-3794</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3796">CVE-2009-3796</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3797">CVE-2009-3797</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3798">CVE-2009-3798</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3799">CVE-2009-3799</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3800">CVE-2009-3800</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3951">CVE-2009-3951</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in December 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3794">CVE-2009-3794</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.jpeg.parsing.heap.overflow.html">Adobe.Flash.Player.JPEG.Parsing.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3797">CVE-2009-3797</a></td><td><a1 href="/encyclopedia/vulnerability/fg-vd-09-024-adobe(real name: adobe.flash.getproperty.memory.corruption).html">FG-VD-09-024-Adobe (real name: Adobe.Flash.Getproperty.Memory.Corruption)</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3798">CVE-2009-3798</a></td><td><a1 href="/encyclopedia/vulnerability/fg-vd-09-026-adobe(real name:  adobe.flash.class.switch.memory.corruption).html">FG-VD-09-026-Adobe (real name:  Adobe.Flash.Class.Switch.Memory.Corruption)</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3951">CVE-2009-3951</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.local.file.check.disclosure.html">Adobe.Flash.Local.File.Check.Disclosure</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, December 8, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for December 2009: <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">http://www.adobe.com/support/security/bulletins/apsb09-19.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-46.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-46.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Adobe Flash Player Vulnerabilities (APSB09-19)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs discovers multiple vulnerabilities in Adobe Flash Player.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of product versions affected, please see the Adobe Security Bulletin reference below. <br /><br /><b>Additional Information:</b><br /><br />Two vulnerabilities were discovered in Adobe Flash, each of which are highlighted below:<br /><ul><li>FG-VD-09-024: Memory corruption vulnerability in "Flash10.ocx" (CVE-2009-3797)</li><li>FG-VD-09-026: Memory corruption vulnerability in "Flash10.ocx" (CVE-2009-3798)</li></ul><br /><b>Solutions:</b><br /><br />FortiGuard Labs released the following signatures:<ul><li>"Adobe.Flash.Getproperty.Memory.Corruption" (CVE-2009-3797)</li><li>"Adobe.Flash.Class.Switch.Memory.Corruption" (CVE-2009-3798)</li><br /><li>Use the solution provided by Adobe (<a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">APSB09-19</a>)</li></ul>FortiGuard Labs continues to monitor attacks against these vulnerabilities.              <br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against these vulnerabilities. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">http://www.adobe.com/support/security/bulletins/apsb09-19.html</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3797">CVE-2009-3797</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3798">CVE-2009-3798</a></li></ul><br /><b>Acknowlegement:</b><br /><br />Bing Liu of Fortinet's FortiGuard Labs<ul><li>For Discovering: CVE-2009-3797, CVE-2009-3798</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-43.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-43.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Microsoft Office Project Vulnerability (MS09-074)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs Discovers Memory Corruption Vulnerability in Microsoft Office Project.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Bulletin reference below.<br /><br /><b>Additional Information:</b><br /><br />The vulnerability lies in "winproj.exe", which is used when processing a Project file. A maliciously crafted document may contain a list structure with a malformed element field, that when processed, will result in memory corruption and allow a remote attacker to arbitrarily execute code on the victims machine.<br /><br /><b>Solutions:</b><br /><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx">MS09-074</a>).</li><li>FortiGuard Labs released a signature "MS.Project.Props.List.Memory.Corruption", which covers this specific vulnerability.</li></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.     <br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx</a></li><li>CVE ID: <a href = "http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0102">CVE-2009-0102</a></li></ul><br /><b>Acknowlegement:</b><br /><br /><ul><li>Bing Liu of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-44.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-44.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Vulnerability in Indeo Codec</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs Discovers Memory Corruption Vulnerability in Indeo Codec.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Security Advisory reference below.<br /><br /><b>Additional Information:</b><br /><br />The Indeo codec on systems running Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow code to run on users systems when opening specially crafted content. There are multiple ways that the Indeo codec may be used and may be required by certain applications. The Indeo codec may be required when visiting legitimate Web sites, and in corporate environment line-of-business applications.<br /><br /><b>Solutions:</b><br /><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/advisory/954157.MSpx">Microsoft Security Advisory 954157</a>).</li><li>FortiGuard Labs released a signature "MS.Windows.Indeo.Codec.Memory.Corruption", which covers this specific vulnerability.</li></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.<br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/954157.MSpx">http://www.microsoft.com/technet/security/advisory/954157.MSpx"</a></li><li>Microsoft Knowledge Base Article: <a href="http://support.microsoft.com/kb/954157">http://support.microsoft.com/kb/954157</a></li><li>CVE ID: <a href = "http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4210">CVE-2009-4210</a></li></ul><br /><b>Acknowlegement:</b><br /><br /><ul><li>Bing Liu of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-45.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-45.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for December 2009 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for December.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-069.mspx">MS09-069</a></td><td>Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3675">CVE-2009-3675</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-070.mspx">MS09-070</a></td><td>Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2508">CVE-2009-2508</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2509">CVE-2009-2509</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-071.mspx">MS09-071</a></td><td>Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2505">CVE-2009-2505</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3677">CVE-2009-3677</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-072.mspx">MS09-072</a></td><td>Cumulative Security Update for Internet Explorer (976325)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2493">CVE-2009-2493</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3671">CVE-2009-3671</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3672">CVE-2009-3672</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3673">CVE-2009-3673</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3674">CVE-2009-3674</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-073.mspx">MS09-073</a></td><td>Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2506">CVE-2009-2506</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx">MS09-074</a></td><td>Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0102">CVE-2009-0102</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in December 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2509">CVE-2009-2509</a></td><td><a1 href="/encyclopedia/vulnerability/ms.adfs.malformed.http.header.code.execution.html">MS.ADFS.Malformed.HTTP.Header.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3677">CVE-2009-3677</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ias.privilege.elevation.html">MS.IAS.Privilege.Elevation</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2493">CVE-2009-2493</a></td><td><a1 href="/encyclopedia/vulnerability/ms.atl.object.type.mismatch.code.execution.html">MS.ATL.Object.Type.Mismatch.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3671">CVE-2009-3671</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.dom.operation.memory.corruption.html">MS.IE.DOM.Operation.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3672">CVE-2009-3672</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.getelementsbytagname.css.handling.code.execution.html">MS.IE.GetElementsByTagName.CSS.Handling.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3674">CVE-2009-3674</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.dom.operation.circular.reference.memory.corruption.html">MS.IE.DOM.Operation.Circular.Reference.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2506">CVE-2009-2506</a></td><td><a1 href="/encyclopedia/vulnerability/ms.word.text.converter.memory.corruption.html">MS.Word.Text.Converter.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0102">CVE-2009-0102</a></td><td><a1 href="/encyclopedia/vulnerability/ms.project.props.list.memory.corruption.html">MS.Project.Props.List.Memory.Corruption</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, December 08 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for December 2009: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-dec.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-dec.mspx</a></li></ul>  ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-42.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-42.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - November 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period October 21st - November 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of all cases reported this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Figure 1a below shows the Top 5 regions attacked in comparison to total attack cases reported this period. Critical issues are outlined in bold.<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>31.9</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption/td><td>22.6</td><td><b>Critical</b></td>        </tr>	<tr>		<td>3</td><td class="left">Adobe.Products.SWF.Remote.Code.Execution</td><td>12.9</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">FTP.USER.Command.Overflow</td><td>9.8</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">Apache.Expect.Header.XSS</td><td>7.8</td><td>Medium</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>7.8</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>6.4</td><td><b>Critical</b></td>        </tr>        <tr class="odd">	<td>8</td><td class="left">MS.DirectX.MsVidCtl.ActiveX.Control.Access</td><td>6.1</td><td><b>Critical</b></td>        </tr>	<tr>		<td>9</td><td class="left">RoundCube.Webmail.Pregreplace.Code.Execution</td><td>5.9</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">FTP.Command.REST.Overflow</td><td>3.2</td><td>High</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape1109/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1109/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by number of attack cases</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 115 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 35 were reported to be actively exploited (30.4%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1109/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1109/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/Cutwail.K!tr</td><td>19.8</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Cutwail.C!tr.dldr</td><td>13.7</td><td><b>new</b></td>        </tr>	<tr><td>3</td><td class="left">W32/Agent.C659!tr.dldr</td><td>9.0</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">W32/PackAgent!tr</td><td>8.3</td><td><b>new</b></td>        </tr>	<tr><td>5</td><td class="left">W32/Zbot!tr</td><td>7.2</td><td><b>+10</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/FraudLoad.DFN!tr</td><td>6.4</td><td><b>new</b></td>        </tr>	<tr><td>7</td><td class="left">W32/FakeAlert.SYY!tr.dldr</td><td>6.3</td><td>-2</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/Zbot.P!tr</td><td>3.3</td><td><b>new</b></td>        </]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_november_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_november_2009.html</guid>
		<pubDate>Fri, 27 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Vulnerability in Internet Explorer Could Allow Remote Code Execution </title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs investigates a remote code execution vulnerability in Internet Explorer.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution<br /><br /> <b>Risk:</b><br /><br /> Critical.<br /><br />  <b>Affected Software:</b><br /><br />For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br /><br /><b>Additional Information:</b><br /><br />The vulnerability results from a JScript execution that may cause memory corruption. This memory space is then accessible to a remote attacker, who is able to crash Internet Explorer and execute arbitrary code.<br /><br /><b>Solutions:</b><br /><br />FortiGuard Labs released the following signature:<ul><li>" MS.IE.GetElementsByTagName.CSS.Handling.Code.Execution" </li></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.<br /><br />Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /> <b>References:</b> <br /> <ul> <li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/977981.mspx">http://www.microsoft.com/technet/security/advisory/977981.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3762">CVE-2009-3762</a></li></ul>	<br />]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-41.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-41.html</guid>
		<pubDate>Wed, 25 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for November 2009</title>
		<description>
		<![CDATA[<br> The table below lists the Microsoft vulnerabilities for November.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-063.mspx">MS09-063</a></td><td>Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2512">CVE-2009-2512</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-064.mspx">MS09-064</a></td><td>Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2523">CVE-2009-2523</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-065.mspx">MS09-065</a></td><td>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1127">CVE-2009-1127</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2513">CVE-2009-2513</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2514">CVE-2009-2514</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-066.mspx">MS09-066</a></td><td>Vulnerability in Active Directory Could Allow Denial of Service (973309)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1928">CVE-2009-1928</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-067.mspx">MS09-067</a></td><td>Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3127">CVE-2009-3127</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3128">CVE-2009-3128</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3129">CVE-2009-3129</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3130">CVE-2009-3130</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3131">CVE-2009-3131</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3132">CVE-2009-3132</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3133">CVE-2009-3133</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3134">CVE-2009-3134</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-068.mspx">MS09-068</a></td><td>Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3135">CVE-2009-3135</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in November 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2512">CVE-2009-2512</a></td><td><a1 href="/encyclopedia/vulnerability/ms.wsdapi.message.handling.memory.corruption.html">MS.WSDAPI.Message.Handling.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2523">CVE-2009-2523</a></td><td><a1 href="/encyclopedia/vulnerability/ms.license.logging.server.rpc.code.execution.html">MS.License.Logging.Server.RPC.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2514">CVE-2009-2514</a></td><td><a1 href="/encyclopedia/vulnerability/ms.kernel.font.parsing.integer.overflow.html">MS.Kernel.Font.Parsing.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1928">CVE-2009-1928</a></td><td><a1 href="/encyclopedia/vulnerability/lsass.ldap.stack.overflow.html">LSASS.LDAP.Stack.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3127">CVE-2009-3127</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.sxdb.record.type.code.execution.html">MS.Office.Excel.SXDB.Record.Type.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3128">CVE-2009-3128</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.sxview.record.code.execution.html">MS.Office.Excel.SxView.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3129">CVE-2009-3129</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.feathdr.biff.record.code.execution.html">MS.Office.Excel.FeatHdr.BIFF.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3130">CVE-2009-3130</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.row.record.integer.field.code.execution.html">MS.Office.Excel.Row.Record.Integer.Field.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3131">CVE-2009-3131</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.formula.record.code.execution.html">MS.Office.Excel.Formula.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3132">CVE-2009-3132</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.formula.ptg.code.execution.html">MS.Office.Excel.Formula.Ptg.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3134">CVE-2009-3134</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.startobject.record.code.execution.html">MS.Office.Excel.StartObject.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="ht]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-40.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-40.html</guid>
		<pubDate>Tue, 10 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities (APSB09-16)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs investigates multiple vulnerabilities in Adobe Shockwave Player.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution / Denial of Service (DoS).<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a full list of affected software, please refer to the Adobe security advisory below.<br /><br /><b>Additional Information:</b><br /><br />Macromedia Director (acquired by Adobe in 2005) can create movie or animation project which includes project resources, links to externally referenced files, scripting code, timeline, etc.. Director movies can only be opened with the Director version used to create the file or a newer version; some Director movies may be opened in Adobe Shockwave Player. However, several vulnerabilities exist in Shockwave Player when handling specially crafted Director movie files, which could result in arbitrary code execution or denial of service.<br /><br /><b>Solutions:</b><br /><br />FortiGuard Labs released the following signatures:<ul><li>"Adobe.ShockWave.Player.ActiveX.Buffer.Overflow" (CVE-2009-3244)</li><li>"Adobe.Shockwave.Player.Dir.File.Invalid.Index.Code.Execution" (CVE-2009-3463)</li><li>"Adobe.Shockwave.Player.Dir.File.Invalid.Pointer.Code.Execution" (CVE-2009-3464)</li><li>"Adobe.Shockwave.Player.Dir.File.Pointer.Handing.Code.Execution" (CVE-2009-3465)</li><li>"Adobe.Shockwave.Player.Dir.File.Invalid.String.Length.DoS" (CVE-2009-3466)</li></ul>FortiGuard Labs continues to monitor attacks against these vulnerabilities.<br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against these vulnerabilities. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Adobe Security Advisory: <a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html">http://www.adobe.com/support/security/bulletins/apsb09-16.html</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3244">CVE-2009-3244</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3463">CVE-2009-3463</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3464">CVE-2009-3464</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3465">CVE-2009-3465</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3466">CVE-2009-3466</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-39.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-39.html</guid>
		<pubDate>Wed, 04 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - October 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period September 21st - October 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of all cases reported this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Figure 1a below shows the Top 5 regions attacked in comparison to total attack cases reported this period. Critical issues are outlined in bold.<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>29.0</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">FTP.USER.Command.Overflow</td><td>24.4</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption</td><td>21.3</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">Adobe.Products.SWF.Remote.Code.Execution</td><td>8.4</td><td><b>Critical</b></td>        </tr>	<tr>		<td>5</td><td class="left">Apache.Expect.Header.XSS</td><td>8.1</td><td>Medium</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>7.6</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>6.7</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>8</td><td class="left">RoundCube.Webmail.Pregreplace.Code.Execution</td><td>5.3</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">MS.DirectX.MsVidCtl.ActiveX.Control.Access</td><td>3.2</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">Apache.MyFaces.Tomahawk.JSF.Framework.XSS</td><td>3.0</td><td>Medium</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape1009/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1009/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by number of attack cases</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 104 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 29 were reported to be actively exploited (27.9%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1009/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1009/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/PackSpam.A!worm</td><td>20.1</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Agent.LGE!tr</td><td>16.9</td><td><b>new</b></td>        </tr>	<tr><td>3</td><td class="left">W32/Bredolab.X!tr</td><td>11.4</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">W32/Bredo.G!tr</td><td>8.2</td><td>-2</td>        </tr>	<tr><td>5</td><td class="left">W32/FakeAlert.SYY!tr.dldr</td><td>7.9</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/Krap.AD!tr</td><td>6.6</td><td><b>new</b></td>        </tr>	<tr><td>7</td><td class="left">W32/OnlineGames.BBR!tr</td><td>3.8</td><td>-6</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/FraudLoad.WSUT!tr.dldr</td><td>1.7</td><td><b>n]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_october_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_october_2009.html</guid>
		<pubDate>Tue, 27 Oct 2009 00:00:00 -0800</pubDate>
	</item>
</channel>
</rss>
