<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>FGCenter - Latest Threats, Advisories, Reports and News</title>
<link>http://www.fortiguard.com/</link>
<language>en</language>
<copyright>Copyright 2010 Fortinet Inc. All Rights Reserved</copyright>
<pubDate>Tue, 09 Feb 2010 05:20:00 -0800</pubDate>
	<item>
		<title>Fortinet Investigates Oracle Privilege Escalation Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br> Fortinet's FortiGuard Labs Investigates a Vulnerability in Oracle.<br><br> <b>Impact:</b><br><br>Remote Command Execution<br><br><b>Risk:</b><br><br>Critical<br><br><b>Affected Software:</b><br> <br> For a list of Oracle versions affected, please see the BugTraq reference below.<br><br><b>Additional Information:</b><br><br>It is possible for a low priviledged users to grant themselves arbitrary permissions through an overly permissive default grant.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><br><b>References:</b><br><ul><li>BugTraq ID:<a href="http://www.securityfocus.com/bid/38115"> 38115 </a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-08.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-08.html</guid>
		<pubDate>Mon, 08 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Protects Against Microsoft Internet Explorer Vulnerability (980088)</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br> Fortinet's FortiGuard Labs Protects Against a Vulnerability in Microsoft Internet Explorer.<br><br> <b>Impact:</b><br> <br> Information Disclosure<br><br><b>Risk:</b><br> <br> High<br> <br><b>Affected Software:</b><br> <br> For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br><br><b>Additional Information:</b><br><br>The vulnerability exists due to content being forced to render incorrectly from local files in such a way that information can be exposed to malicious websites.<br><br>FortiGuard Labs continues to monitor this vulnerability world wide while developing additional mitigation strategies / solutions based off our findings.<br><br><b>Solutions:</b><br><ul><li>Follow the workarounds <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">provided by Microsoft</a> (980088).</li><li>FortiGuard Labs released a signature "MS.0day.18176" on Feb. 05,2010, which covers this specific vulnerability</li></ul><br><br>Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><ul><li>Microsoft Advisory: <a href="http://www.microsoft.com/technet/security/advisory/980088.mspx">http://www.microsoft.com/technet/security/advisory/980088.mspx</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0255">CVE-2010-0255</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-07.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-07.html</guid>
		<pubDate>Thu, 04 Feb 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - January 2010 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period December 21st, 2009 - January 20th, 2010.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />Top 10 attack attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the attack's debut in the Top 100. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th><th>Top 100 Shift</th>	</tr>	<tr>		<td>1</td><td class="left">Gumblar.Botnet</td><td>31.3</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>24.3</td><td><b>Critical</b></td><td>-1</td>        </tr>	<tr>		<td>3</td><td class="left">Waledac.Botnet</td><td>7.6</td><td><b>Critical</b></td><td>-1</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.IE.Event.Invalid.Pointer.Memory.Corruption</td><td>7.4</td><td><b>Critical</b></td><td><b>new</b></td>        </tr>	<tr>		<td>5</td><td class="left">Adobe.Products.SWF.Remote.Code.Execution</td><td>6.9</td><td><b>Critical</b></td><td><b>+6</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption</td><td>6.5</td><td><b>Critical</b></td><td>-</td>        </tr>	<tr>		<td>7</td><td class="left">FTP.USER.Command.Overflow</td><td>6.1</td><td>High</td><td>-3</td>        </tr>        <tr class="odd">	<td>8</td><td class="left">Apache.Expect.Header.XSS</td><td>6.0</td><td>Medium</td><td>-</td>        </tr>	<tr>		<td>9</td><td class="left">Adobe.Reader.Printf.Buffer.Overflow</td><td>5.8</td><td><b>Critical</b></td><td><b>+10</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>5.8</td><td>High</td><td>-7</td>        </tr></table><br /><br /><table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0110/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0110/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0110/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0110/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 150 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 34 were reported to be actively exploited (22.7%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0110/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0110/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_january_2010.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_january_2010.html</guid>
		<pubDate>Wed, 27 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Microsoft Internet Explorer Vulnerability (MS10-002)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs has discovered a memory corruption vulnerability in Microsoft's Internet Explorer.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> Critical.<br> <br> <b>Affected Software:</b><br> <br> For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br><br> <b>Additional Information:</b><br> <br> In order to compromise a system / remotely execute code, an attacker would lure a user to a maliciously crafted website. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. <br><br> <b>Solutions:</b><br> <br> Since an attack scenario would require a user to visit a malicious website, it is recommended to have a layered security solution through webfiltering and intrusion prevention for mitigation.<ul> <li>Use the solution <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">provided by Microsoft</a> (MS10-002).</li><li>FortiGuard Labs released the signature "MS.IE.MergeAttributes.Remote.Code.Execution".</li><ul><li>Advanced zero-day protection has been available since September 3, 2009.</li></ul></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.<br> <br> Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br ><br> <b>References:</b><br> <ul> <li> Microsoft Security Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0247">CVE-2010-0247</a></li></ul> <br><b>Acknowledgment:</b><ul><li>Haifei Li of Fortinet's FortiGuard Labs.</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-05.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-05.html</guid>
		<pubDate>Thu, 21 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for January 21, 2010 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for January 21, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-002.mspx">MS10-002</a></td><td>Cumulative Security Update for Internet Explorer (978207)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4074">CVE-2009-4074</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0027">CVE-2010-0027</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0244">CVE-2010-0244</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0245">CVE-2010-0245</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0246">CVE-2010-0246</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0247">CVE-2010-0247</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0248">CVE-2010-0248</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0249">CVE-2010-0249</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in January 21, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0244">CVE-2010-0244</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.object.handler.memory.corruption.html">MS.IE.Object.Handler.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0245">CVE-2010-0245</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.dom.operation.memory.corruption.html">MS.IE.DOM.Operation.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0246">CVE-2010-0246</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie8.uninitialized.memory.corruption.html">MS.IE8.Uninitialized.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0247">CVE-2010-0247</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.mergeattributes.remote.code.execution.html">MS.IE.MergeAttributes.Remote.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0248">CVE-2010-0248</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.html.removed.table.reference.memory.corruption.html">MS.IE.HTML.Removed.Table.Reference.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0249">CVE-2010-0249</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.event.invalid.pointer.memory.corruption.html">MS.IE.Event.Invalid.Pointer.Memory.Corruption</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Thursday, January 21 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for January 21, 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-06.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-06.html</guid>
		<pubDate>Thu, 21 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for January 19, 2010</title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on January 19, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-03.html">apsb10-03</a></td><td>Vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system.</td><td align="center">Critical</td><td align="center">Shockwave Player 11.5.2.602 and earlier versions for Windows and Macintosh</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4002">CVE-2009-4002</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4003">CVE-2009-4003</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in January 19, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4002">CVE-2009-4002</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.parsing.heap.overflow.html">Adobe.Shockwave.Player.Dir.File.Parsing.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4003">CVE-2009-4003</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.shockwave.player.dir.file.parsing.integer.overflow.html">Adobe.Shockwave.Player.Dir.File.Parsing.Integer.Overflow</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Thursday, January 19 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for January 19, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-03.html">http://www.adobe.com/support/security/bulletins/apsb10-03.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-04.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-04.html</guid>
		<pubDate>Tue, 19 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Vulnerability in Internet Explorer Could Allow Remote Code Execution (979352)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs protects against a remote code execution vulnerability in Internet Explorer.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> Critical.<br> <br> <b>Affected Software:</b><br> <br> For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br><br> <b>Additional Information:</b><br> <br> The vulnerability exists as an invalid pointer reference within Internet Explorer. It is possible under certain conditions for the invalid pointer to be accessed after an object is deleted. In a specially-crafted attack, in attempting to access a freed object, Internet Explorer can be caused to allow remote code execution. In order to compromise a system / remotely execute code, an attacker would lure a user to a maliciously crafted website.<br><br> <b>Solutions:</b><br> <br> Since an attack scenario would require a user to visit a malicious website, it is recommended to have a layered security solution through webfiltering and intrusion prevention for mitigation.<br ><br ><b>Updated:</b> January 21, 2009<ul> <li> Use the solution <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">provided by Microsoft</a>.</li><li>FortiGuard Labs released the signature "MS.IE.Event.Invalid.Pointer.Memory.Corruption" (CVE-2010-0249).</li> </ul> FortiGuard Labs continues to monitor attacks against this vulnerability.<br> <br> Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br ><br> <b>References:</b><br> <ul> <li>Microsoft Security Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-002.mspx</a></li><li> Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/979352.mspx">http://www.microsoft.com/technet/security/advisory/979352.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0249">CVE-2010-0249</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-03.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-03.html</guid>
		<pubDate>Mon, 18 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for January 12, 2010 </title>
		<description>
		<![CDATA[The table below lists the vulnerabilities addressed by Adobe on January 12, 2010.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="20%">Affected Software</th><th width="27%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">apsb10-02</a></td><td>Vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center">Adobe Reader 9.2 and earlier versions for Windows, Macintosh, and UNIX,Adobe Acrobat 9.2 and earlier versions for Windows and Macintosh</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3953">CVE-2009-3953</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3954">CVE-2009-3954</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3955">CVE-2009-3955</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3956">CVE-2009-3956</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3957">CVE-2009-3957</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3958">CVE-2009-3958</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3959">CVE-2009-3959</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4324">CVE-2009-4324</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in January 12, 2010.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3953">CVE-2009-3953</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.u3d.clod.mesh.declaration.array.buffer.overflow.html">Adobe.U3D.CLOD.Mesh.Declaration.Array.Buffer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3955">CVE-2009-3955</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.jpxdecode.jp2c.stream.memory.corruption.html">Adobe.Reader.JpxDecode.Jp2c.Stream.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3956">CVE-2009-3956</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.fdf.javascript.execution.html">Adobe.Reader.FDF.Javascript.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3957">CVE-2009-3957</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.pdf.colors.code.execution.html">Adobe.PDF.Colors.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3958">CVE-2009-3958</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.get.atlcom.activex.control.access.html">Adobe.Get.Atlcom.ActiveX.Control.Access</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3959">CVE-2009-3959</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.reader.u3d.content.integer.overflow.html">Adobe.Acrobat.Reader.U3D.Content.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4324">CVE-2009-4324</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.javascript.newplayer.method.code.execution.html">Adobe.Reader.Javascript.newplayer.Method.Code.Execution</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, January 12 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for January 12, 2010: <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">http://www.adobe.com/support/security/bulletins/apsb10-02.html</a></li></ul>  ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-02.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-02.html</guid>
		<pubDate>Tue, 12 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for January 2010</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for January.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS10-001.mspx">MS10-001</a></td><td>Vulnerability in the Embedded OpenType Font Engine Could Allow Remote Code Execution (972270)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0018">CVE-2010-0018</a>  </td></tr>  </table> <br /><br />   <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, January 12 2010</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for January 2010: <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2010-01.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2010-01.html</guid>
		<pubDate>Tue, 12 Jan 2010 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - December 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period November 21st - December 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Attacks & Regions</u></h3><br /><br />Top 10 attack attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of the accumulated daily incidents reported during this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Critical issues are outlined in bold. Figure 1a shows a daily record of attack cases reported for this period's Top 5 attacks. Figure 1b below shows the Top 5 regions attacked in comparison to total attack cases reported this period. <br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>55.6</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">Waledac.Botnet</td><td>8.2</td><td><b>Critical</b></td>        </tr>	<tr>		<td>3</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>6.1</td><td>High</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">FTP.USER.Command.Overflow</td><td>4.6</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">MS.Windows.LSASS.Buffer.Overflow</td><td>4.5</td><td>High</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption</td><td>3.7</td><td><b>Critical</b></td>        </tr>	<tr>		<td>7</td><td class="left">SMTP.Auth.Buffer.Overflow</td><td>3.1</td><td><b>Critical</b></td>        </tr>        <tr class="odd">	<td>8</td><td class="left">Apache.Expect.Header.XSS</td><td>2.5</td><td>Medium</td>        </tr>	<tr>		<td>9</td><td class="left">Apache.MyFaces.Tomahawk.JSF.Framework.XSS</td><td>2.4</td><td>Medium</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">FTP.Command.REST.Overflow</td><td>2.3</td><td>High</td>        </tr></table><br /><br /><table cellpadding="5" cellspacing="5" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1209/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1209/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Daily attack case activity for top 5 attacks</i></center></td><td width="50%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1209/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1209/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: Top 5 regions by number of attack cases</i></center></td></tr></table></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 157 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 46 were reported to be actively exploited (29.3%).</i><br /><br />Figure 1c breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1209/image-01c.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1209/image-01c.png" width="160" height="110"></a><br /><i>Figure 1c: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/PackBredolab.C!tr</td><td>66.5</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">JS/PackRedir.A!tr.dldr</td><td>6.8</td><td><b>+17</b></td>        </tr>	<tr><td>3</td><td class="left">JS/Feebs.A@mm</td><td>2.2</td><td><b>+14</b></td>        </tr>        <tr class="odd"><td]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_december_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_december_2009.html</guid>
		<pubDate>Thu, 24 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for December 18, 2009</title>
		<description>
		<![CDATA[The table below lists the Adobe vulnerabilities for December.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="15%"> </th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb09-18.html">apsb09-18</a></td><td>Vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system.</td><td align="center">Critical</td><td align="center"></td><td>Flash Media Server 3.5.2 and earlier versions</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3791">CVE-2009-3791</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3792">CVE-2009-3792</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in December 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3791">CVE-2009-3791</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.media.server.resource.exhaustion.dos.html">Adobe.Flash.Media.Server.Resource.Exhaustion.DoS</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3792">CVE-2009-3792</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.media.server.directory.traversal.html">Adobe.Flash.Media.Server.Directory.Traversal</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Friday, December 18 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for December 2009: <a href="http://www.adobe.com/support/security/bulletins/apsb09-18.html">http://www.adobe.com/support/security/bulletins/apsb09-18.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-49.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-49.html</guid>
		<pubDate>Fri, 18 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Multiple Cisco WebEx WRF Player Vulnerabilities</title>
		<description>
		<![CDATA[<strong>Summary:</strong><p />Multiple memory corruption vulnerabilities exist in Cisco WebEx WRF Player which allow a remote attacker to compromise a vulnerable system.<p /><strong>Impact:</strong><p />Remote code execution / Denial of service.<p /><strong>Risk:</strong><p /> <ul><li> Critical</li></ul><p /><strong>Affected Software:</strong><p /> <ul><li> Cisco WebEx WRF Player 3.0 or earlier versions on Linux,Microsoft Windows and Mac OS X</li></ul><p /><strong>Additional Information:</strong><p />Six vulnerabilities were discovered in Cisco WebEx WRF Player, each of which is highlighted below:<p /> <ul><li> FG-VD-09-008: Cisco WebEx WRF Player Denial Of Service in "atrpui.dll" (CVE-2009-2880)</li> <li> FG-VD-09-010: Cisco WebEx WRF Player Heap Overflow in "atas32.dll" (CVE-2009-2879)</li> <li> FG-VD-09-012: Cisco WebEx WRF Player Heap Overflow in "atas32.dll" (CVE-2009-2876)</li> <li> FG-VD-09-013: Cisco WebEx WRF Player Heap Overflow in "atas32.dll" (CVE-2009-2878)</li> <li> FG-VD-09-014: Cisco WebEx WRF Player Stack Overflow in "ataudio.dll" (CVE-2009-2877)</li> <li> FG-VD-09-016: Cisco WebEx WRF Player Denial of Service in "atas32.dll" (CVE-2009-2875)</li></ul><p /><strong>Solutions:</strong><p />Use the <a href="http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml">solution provided by Cisco:</a>    <ul><li> FG-VD-09-008: fixed in WebEx releases T26 and T27</li> <li> FG-VD-09-010: fixed in WebEx releases T26SP49EP32 and T27SP10</li> <li> FG-VD-09-012: fixed in WebEx releases T26SP49EP32 and T27SP10</li> <li> FG-VD-09-013: fixed in WebEx releases T26SP49EP32 and T27SP10</li> <li> FG-VD-09-014: fixed in WebEx releases T26LSp49EP32 and T27SP10</li> <li> FG-VD-09-016: fixed in WebEx release T26SP49EP</li></ul>          <p /> FortiGuard Labs released the following signatures to protect against these vulnerabilities <ul><li> "Cisco.WebEx.Player.atas32.Heap.Overflow" (CVE-2009-2879, CVE-2009-2876, CVE-2009-2878)</li> <li> "Cisco.WebEx.Player.ataudio.Buffer.Overflow" (CVE-2009-2877)</li> <li> "Cisco.WebEx.Player.atrpui.DoS" (CVE-2009-2880)</li> <li> "Cisco.WebEx.Player.atas32.DoS" (CVE-2009-2875)</li></ul><p /><p /><p />Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against these memory corruption vulnerabilities. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by Fortinet's FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<p /><strong>References:</strong><p /> <ul><li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2880">CVE-2009-2880</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2879">CVE-2009-2879</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2876">CVE-2009-2876</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2878">CVE-2009-2878</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2877">CVE-2009-2877</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2875">CVE-2009-2875</a></li> <li> Cisco Security Advisory: <a href="http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml">http://www.cisco.com/warp/public/707/cisco-sa-20091216-webex.shtml</a></li></ul><p /><p /><strong>Acknowledgment:</strong><p /> <ul><li>  Zhenhua Liu and XiaoPeng Zhang of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-48.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-48.html</guid>
		<pubDate>Wed, 16 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Reader / Acrobat Remote Code Execution Vulnerability (APSA09-07)</title>
		<description>
		<![CDATA[<b>Summary:</b><br> <br> Fortinet's FortiGuard Labs investigates a vulnerability in Adobe Acrobat / Adobe Reader that leads to remote code execution.<br> <br> <b>Impact:</b><br> <br> Remote Code Execution.<br> <br> <b>Risk:</b><br> <br> Critical.<br> <br> <b>Affected Software:</b><br> <br> For a list of product versions affected, please see the Adobe Security Advisory reference below.<br><br> <b>Additional Information:</b><br> <br> Attacks have been spotted in the wild which exploit this vulnerability through a maliciously crafted PDF file using Javascript functions. When the document is opened, further malicious components are typically downloaded for execution. FortiGuard Labs continues to monitor attacks against this vulnerability.<br> <br> <b>Solutions:</b><br> <br> <ul> <li> Use the solution provided <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html" id="uk15" title="suggested by Adobe">by Adobe</a> (APSA09-07).<br> </li> <li> FortiGuard Labs released the signature "Adobe.Reader.Javascript.newplayer.Method.Code.Execution" (CVE-2009-4324).</li> </ul> <br> <br> Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by Fortinet's FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br> <br> <b>References:</b><br> <ul> <li> Adobe Security Advisory: <a title="http://www.adobe.com/support/security/advisories/apsa09-07.html" href="http://www.adobe.com/support/security/advisories/apsa09-07.html" id="hqkx">http://www.adobe.com/support/security/advisories/apsa09-07.html</a></li> <li> CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3244">CVE-2009-4324</a> </li> </ul> <br> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-47.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-47.html</guid>
		<pubDate>Tue, 15 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for December 08, 2009 </title>
		<description>
		<![CDATA[The table below lists the Adobe vulnerabilities for December.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="15%"> </th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">APSB09-19</a></td><td>Vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center"> </td><td>Adobe Flash Player 10.0.32.18 and earlier versions,Adobe AIR 1.5.2 and earlier versions</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3794">CVE-2009-3794</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3796">CVE-2009-3796</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3797">CVE-2009-3797</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3798">CVE-2009-3798</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3799">CVE-2009-3799</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3800">CVE-2009-3800</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3951">CVE-2009-3951</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in December 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3794">CVE-2009-3794</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.player.jpeg.parsing.heap.overflow.html">Adobe.Flash.Player.JPEG.Parsing.Heap.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3797">CVE-2009-3797</a></td><td><a1 href="/encyclopedia/vulnerability/fg-vd-09-024-adobe(real name: adobe.flash.getproperty.memory.corruption).html">FG-VD-09-024-Adobe (real name: Adobe.Flash.Getproperty.Memory.Corruption)</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3798">CVE-2009-3798</a></td><td><a1 href="/encyclopedia/vulnerability/fg-vd-09-026-adobe(real name:  adobe.flash.class.switch.memory.corruption).html">FG-VD-09-026-Adobe (real name:  Adobe.Flash.Class.Switch.Memory.Corruption)</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3951">CVE-2009-3951</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.flash.local.file.check.disclosure.html">Adobe.Flash.Local.File.Check.Disclosure</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, December 8, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Adobe Security Bulletin Summary for December 2009: <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">http://www.adobe.com/support/security/bulletins/apsb09-19.html</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-46.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-46.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Adobe Flash Player Vulnerabilities (APSB09-19)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs discovers multiple vulnerabilities in Adobe Flash Player.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of product versions affected, please see the Adobe Security Bulletin reference below. <br /><br /><b>Additional Information:</b><br /><br />Two vulnerabilities were discovered in Adobe Flash, each of which are highlighted below:<br /><ul><li>FG-VD-09-024: Memory corruption vulnerability in "Flash10.ocx" (CVE-2009-3797)</li><li>FG-VD-09-026: Memory corruption vulnerability in "Flash10.ocx" (CVE-2009-3798)</li></ul><br /><b>Solutions:</b><br /><br />FortiGuard Labs released the following signatures:<ul><li>"Adobe.Flash.Getproperty.Memory.Corruption" (CVE-2009-3797)</li><li>"Adobe.Flash.Class.Switch.Memory.Corruption" (CVE-2009-3798)</li><br /><li>Use the solution provided by Adobe (<a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">APSB09-19</a>)</li></ul>FortiGuard Labs continues to monitor attacks against these vulnerabilities.              <br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against these vulnerabilities. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html">http://www.adobe.com/support/security/bulletins/apsb09-19.html</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3797">CVE-2009-3797</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3798">CVE-2009-3798</a></li></ul><br /><b>Acknowlegement:</b><br /><br />Bing Liu of Fortinet's FortiGuard Labs<ul><li>For Discovering: CVE-2009-3797, CVE-2009-3798</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-43.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-43.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Microsoft Office Project Vulnerability (MS09-074)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs Discovers Memory Corruption Vulnerability in Microsoft Office Project.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Bulletin reference below.<br /><br /><b>Additional Information:</b><br /><br />The vulnerability lies in "winproj.exe", which is used when processing a Project file. A maliciously crafted document may contain a list structure with a malformed element field, that when processed, will result in memory corruption and allow a remote attacker to arbitrarily execute code on the victims machine.<br /><br /><b>Solutions:</b><br /><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx">MS09-074</a>).</li><li>FortiGuard Labs released a signature "MS.Project.Props.List.Memory.Corruption", which covers this specific vulnerability.</li></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.     <br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-074.mspx</a></li><li>CVE ID: <a href = "http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0102">CVE-2009-0102</a></li></ul><br /><b>Acknowlegement:</b><br /><br /><ul><li>Bing Liu of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-44.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-44.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Discovers Vulnerability in Indeo Codec</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs Discovers Memory Corruption Vulnerability in Indeo Codec.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Security Advisory reference below.<br /><br /><b>Additional Information:</b><br /><br />The Indeo codec on systems running Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow code to run on users systems when opening specially crafted content. There are multiple ways that the Indeo codec may be used and may be required by certain applications. The Indeo codec may be required when visiting legitimate Web sites, and in corporate environment line-of-business applications.<br /><br /><b>Solutions:</b><br /><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/advisory/954157.MSpx">Microsoft Security Advisory 954157</a>).</li><li>FortiGuard Labs released a signature "MS.Windows.Indeo.Codec.Memory.Corruption", which covers this specific vulnerability.</li></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.<br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by FortiGuard Labs, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/954157.MSpx">http://www.microsoft.com/technet/security/advisory/954157.MSpx"</a></li><li>Microsoft Knowledge Base Article: <a href="http://support.microsoft.com/kb/954157">http://support.microsoft.com/kb/954157</a></li><li>CVE ID: <a href = "http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-4210">CVE-2009-4210</a></li></ul><br /><b>Acknowlegement:</b><br /><br /><ul><li>Bing Liu of Fortinet's FortiGuard Labs</li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-45.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-45.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for December 2009 </title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for December.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-069.mspx">MS09-069</a></td><td>Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (974392)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3675">CVE-2009-3675</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-070.mspx">MS09-070</a></td><td>Vulnerabilities in Active Directory Federation Services Could Allow Remote Code Execution (971726)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2508">CVE-2009-2508</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2509">CVE-2009-2509</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-071.mspx">MS09-071</a></td><td>Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2505">CVE-2009-2505</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3677">CVE-2009-3677</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-072.mspx">MS09-072</a></td><td>Cumulative Security Update for Internet Explorer (976325)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2493">CVE-2009-2493</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3671">CVE-2009-3671</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3672">CVE-2009-3672</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3673">CVE-2009-3673</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3674">CVE-2009-3674</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-073.mspx">MS09-073</a></td><td>Vulnerability in WordPad and Office Text Converters Could Allow Remote Code Execution (975539)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2506">CVE-2009-2506</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-074.mspx">MS09-074</a></td><td>Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0102">CVE-2009-0102</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in December 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2509">CVE-2009-2509</a></td><td><a1 href="/encyclopedia/vulnerability/ms.adfs.malformed.http.header.code.execution.html">MS.ADFS.Malformed.HTTP.Header.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3677">CVE-2009-3677</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ias.privilege.elevation.html">MS.IAS.Privilege.Elevation</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2493">CVE-2009-2493</a></td><td><a1 href="/encyclopedia/vulnerability/ms.atl.object.type.mismatch.code.execution.html">MS.ATL.Object.Type.Mismatch.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3671">CVE-2009-3671</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.dom.operation.memory.corruption.html">MS.IE.DOM.Operation.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3672">CVE-2009-3672</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.getelementsbytagname.css.handling.code.execution.html">MS.IE.GetElementsByTagName.CSS.Handling.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3674">CVE-2009-3674</a></td><td><a1 href="/encyclopedia/vulnerability/ms.ie.dom.operation.circular.reference.memory.corruption.html">MS.IE.DOM.Operation.Circular.Reference.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2506">CVE-2009-2506</a></td><td><a1 href="/encyclopedia/vulnerability/ms.word.text.converter.memory.corruption.html">MS.Word.Text.Converter.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0102">CVE-2009-0102</a></td><td><a1 href="/encyclopedia/vulnerability/ms.project.props.list.memory.corruption.html">MS.Project.Props.List.Memory.Corruption</a1></td></tr>  </table> <br />  For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br />  <br /><br />  <h2 class="title">Document History</h2><br />  <table class="threats"> <tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr> <tr><td align="center">Tuesday, December 08 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr> </table>  <br /><br />  <b>Reference:</b><br /> <ul><li>Microsoft Security Bulletin Summary for December 2009: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-dec.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-dec.mspx</a></li></ul>  ]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-42.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-42.html</guid>
		<pubDate>Tue, 08 Dec 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - November 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period October 21st - November 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of all cases reported this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Figure 1a below shows the Top 5 regions attacked in comparison to total attack cases reported this period. Critical issues are outlined in bold.<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>31.9</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption/td><td>22.6</td><td><b>Critical</b></td>        </tr>	<tr>		<td>3</td><td class="left">Adobe.Products.SWF.Remote.Code.Execution</td><td>12.9</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">FTP.USER.Command.Overflow</td><td>9.8</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">Apache.Expect.Header.XSS</td><td>7.8</td><td>Medium</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>7.8</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>6.4</td><td><b>Critical</b></td>        </tr>        <tr class="odd">	<td>8</td><td class="left">MS.DirectX.MsVidCtl.ActiveX.Control.Access</td><td>6.1</td><td><b>Critical</b></td>        </tr>	<tr>		<td>9</td><td class="left">RoundCube.Webmail.Pregreplace.Code.Execution</td><td>5.9</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">FTP.Command.REST.Overflow</td><td>3.2</td><td>High</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape1109/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1109/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by number of attack cases</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 115 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 35 were reported to be actively exploited (30.4%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1109/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1109/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/Cutwail.K!tr</td><td>19.8</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Cutwail.C!tr.dldr</td><td>13.7</td><td><b>new</b></td>        </tr>	<tr><td>3</td><td class="left">W32/Agent.C659!tr.dldr</td><td>9.0</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">W32/PackAgent!tr</td><td>8.3</td><td><b>new</b></td>        </tr>	<tr><td>5</td><td class="left">W32/Zbot!tr</td><td>7.2</td><td><b>+10</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/FraudLoad.DFN!tr</td><td>6.4</td><td><b>new</b></td>        </tr>	<tr><td>7</td><td class="left">W32/FakeAlert.SYY!tr.dldr</td><td>6.3</td><td>-2</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/Zbot.P!tr</td><td>3.3</td><td><b>new</b></td>        </]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_november_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_november_2009.html</guid>
		<pubDate>Fri, 27 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Vulnerability in Internet Explorer Could Allow Remote Code Execution </title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs investigates a remote code execution vulnerability in Internet Explorer.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution<br /><br /> <b>Risk:</b><br /><br /> Critical.<br /><br />  <b>Affected Software:</b><br /><br />For a list of Internet Explorer versions affected, please see the Microsoft Security Advisory reference below.<br /><br /><b>Additional Information:</b><br /><br />The vulnerability results from a JScript execution that may cause memory corruption. This memory space is then accessible to a remote attacker, who is able to crash Internet Explorer and execute arbitrary code.<br /><br /><b>Solutions:</b><br /><br />FortiGuard Labs released the following signature:<ul><li>" MS.IE.GetElementsByTagName.CSS.Handling.Code.Execution" </li></ul>FortiGuard Labs continues to monitor attacks against this vulnerability.<br /><br />Fortinet customers who subscribe to Fortinet's intrusion prevention (IPS) service should be protected against this vulnerability. Fortinet's IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /> <b>References:</b> <br /> <ul> <li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/977981.mspx">http://www.microsoft.com/technet/security/advisory/977981.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3762">CVE-2009-3762</a></li></ul>	<br />]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-41.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-41.html</guid>
		<pubDate>Wed, 25 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for November 2009</title>
		<description>
		<![CDATA[<br> The table below lists the Microsoft vulnerabilities for November.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-063.mspx">MS09-063</a></td><td>Vulnerability in Web Services on Devices API Could Allow Remote Code Execution (973565)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2512">CVE-2009-2512</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-064.mspx">MS09-064</a></td><td>Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2523">CVE-2009-2523</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-065.mspx">MS09-065</a></td><td>Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution (969947)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1127">CVE-2009-1127</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2513">CVE-2009-2513</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2514">CVE-2009-2514</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-066.mspx">MS09-066</a></td><td>Vulnerability in Active Directory Could Allow Denial of Service (973309)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1928">CVE-2009-1928</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-067.mspx">MS09-067</a></td><td>Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (972652)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3127">CVE-2009-3127</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3128">CVE-2009-3128</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3129">CVE-2009-3129</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3130">CVE-2009-3130</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3131">CVE-2009-3131</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3132">CVE-2009-3132</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3133">CVE-2009-3133</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3134">CVE-2009-3134</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-068.mspx">MS09-068</a></td><td>Vulnerability in Microsoft Office Word Could Allow Remote Code Execution (976307)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3135">CVE-2009-3135</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Microsoft vulnerabilities in November 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2512">CVE-2009-2512</a></td><td><a1 href="/encyclopedia/vulnerability/ms.wsdapi.message.handling.memory.corruption.html">MS.WSDAPI.Message.Handling.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2523">CVE-2009-2523</a></td><td><a1 href="/encyclopedia/vulnerability/ms.license.logging.server.rpc.code.execution.html">MS.License.Logging.Server.RPC.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2514">CVE-2009-2514</a></td><td><a1 href="/encyclopedia/vulnerability/ms.kernel.font.parsing.integer.overflow.html">MS.Kernel.Font.Parsing.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1928">CVE-2009-1928</a></td><td><a1 href="/encyclopedia/vulnerability/lsass.ldap.stack.overflow.html">LSASS.LDAP.Stack.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3127">CVE-2009-3127</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.sxdb.record.type.code.execution.html">MS.Office.Excel.SXDB.Record.Type.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3128">CVE-2009-3128</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.sxview.record.code.execution.html">MS.Office.Excel.SxView.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3129">CVE-2009-3129</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.feathdr.biff.record.code.execution.html">MS.Office.Excel.FeatHdr.BIFF.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3130">CVE-2009-3130</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.row.record.integer.field.code.execution.html">MS.Office.Excel.Row.Record.Integer.Field.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3131">CVE-2009-3131</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.formula.record.code.execution.html">MS.Office.Excel.Formula.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3132">CVE-2009-3132</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.formula.ptg.code.execution.html">MS.Office.Excel.Formula.Ptg.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3134">CVE-2009-3134</a></td><td><a1 href="/encyclopedia/vulnerability/ms.office.excel.startobject.record.code.execution.html">MS.Office.Excel.StartObject.Record.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="ht]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-40.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-40.html</guid>
		<pubDate>Tue, 10 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Shockwave Player Multiple Remote Code Execution Vulnerabilities (APSB09-16)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Labs investigates multiple vulnerabilities in Adobe Shockwave Player.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution / Denial of Service (DoS).<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a full list of affected software, please refer to the Adobe security advisory below.<br /><br /><b>Additional Information:</b><br /><br />Macromedia Director (acquired by Adobe in 2005) can create movie or animation project which includes project resources, links to externally referenced files, scripting code, timeline, etc.. Director movies can only be opened with the Director version used to create the file or a newer version; some Director movies may be opened in Adobe Shockwave Player. However, several vulnerabilities exist in Shockwave Player when handling specially crafted Director movie files, which could result in arbitrary code execution or denial of service.<br /><br /><b>Solutions:</b><br /><br />FortiGuard Labs released the following signatures:<ul><li>"Adobe.ShockWave.Player.ActiveX.Buffer.Overflow" (CVE-2009-3244)</li><li>"Adobe.Shockwave.Player.Dir.File.Invalid.Index.Code.Execution" (CVE-2009-3463)</li><li>"Adobe.Shockwave.Player.Dir.File.Invalid.Pointer.Code.Execution" (CVE-2009-3464)</li><li>"Adobe.Shockwave.Player.Dir.File.Pointer.Handing.Code.Execution" (CVE-2009-3465)</li><li>"Adobe.Shockwave.Player.Dir.File.Invalid.String.Length.DoS" (CVE-2009-3466)</li></ul>FortiGuard Labs continues to monitor attacks against these vulnerabilities.<br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against these vulnerabilities. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Adobe Security Advisory: <a href="http://www.adobe.com/support/security/bulletins/apsb09-16.html">http://www.adobe.com/support/security/bulletins/apsb09-16.html</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3244">CVE-2009-3244</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3463">CVE-2009-3463</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3464">CVE-2009-3464</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3465">CVE-2009-3465</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3466">CVE-2009-3466</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-39.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-39.html</guid>
		<pubDate>Wed, 04 Nov 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - October 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period September 21st - October 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Labs</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period follows, ranked by the number of valid attack cases reported. Valid attack cases consist only of threats we have listed as a Threat Outbreak on our FortiGuard Center (<a href="http://www.fortiguard.com/rss/latestthreat.xml">RSS feed here</a>). Percentage indicates the portion of activity for which the attack accounted out of all cases reported this period. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from medium to critical. Figure 1a below shows the Top 5 regions attacked in comparison to total attack cases reported this period. Critical issues are outlined in bold.<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>29.0</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">FTP.USER.Command.Overflow</td><td>24.4</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption</td><td>21.3</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">Adobe.Products.SWF.Remote.Code.Execution</td><td>8.4</td><td><b>Critical</b></td>        </tr>	<tr>		<td>5</td><td class="left">Apache.Expect.Header.XSS</td><td>8.1</td><td>Medium</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">AWStats.Rawlog.Plugin.Logfile.Parameter.Input.Validation</td><td>7.6</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.Content.Management.Server.Code.Execution</td><td>6.7</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>8</td><td class="left">RoundCube.Webmail.Pregreplace.Code.Execution</td><td>5.3</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">MS.DirectX.MsVidCtl.ActiveX.Control.Access</td><td>3.2</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">Apache.MyFaces.Tomahawk.JSF.Framework.XSS</td><td>3.0</td><td>Medium</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape1009/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1009/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by number of attack cases</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 104 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 29 were reported to be actively exploited (27.9%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape1009/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape1009/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/PackSpam.A!worm</td><td>20.1</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Agent.LGE!tr</td><td>16.9</td><td><b>new</b></td>        </tr>	<tr><td>3</td><td class="left">W32/Bredolab.X!tr</td><td>11.4</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">W32/Bredo.G!tr</td><td>8.2</td><td>-2</td>        </tr>	<tr><td>5</td><td class="left">W32/FakeAlert.SYY!tr.dldr</td><td>7.9</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/Krap.AD!tr</td><td>6.6</td><td><b>new</b></td>        </tr>	<tr><td>7</td><td class="left">W32/OnlineGames.BBR!tr</td><td>3.8</td><td>-6</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/FraudLoad.WSUT!tr.dldr</td><td>1.7</td><td><b>n]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_october_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_october_2009.html</guid>
		<pubDate>Tue, 27 Oct 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Security Bulletin for October 2009</title>
		<description>
		<![CDATA[<br> The table below lists the Adobe vulnerabilities for October.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>Adobe Vulnerability Identifier </th><th width="33%">Adobe Bulletin Title</th><th width="10%">Severity</th><th width="15%"> </th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">apsb09-15</a></td><td>Vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system.</td><td align="center">Critical</td><td align="center"> </td><td>Adobe Reader 9.1.3 and earlier versions for Windows, Macintosh, and UNIX, Adobe Acrobat 9.1.3 and earlier versions for Windows and Macintosh</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2979">CVE-2009-2979</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2980">CVE-2009-2980</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2984">CVE-2009-2984</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2985">CVE-2009-2985</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2987">CVE-2009-2987</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2988">CVE-2009-2988</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2989">CVE-2009-2989</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2990">CVE-2009-2990</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2991">CVE-2009-2991</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2992">CVE-2009-2992</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2993">CVE-2009-2993</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2994">CVE-2009-2994</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2995">CVE-2009-2995</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2996">CVE-2009-2996</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2997">CVE-2009-2997</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2998">CVE-2009-2998</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3458">CVE-2009-3458</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3460">CVE-2009-3460</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3459">CVE-2009-3459</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0048">CVE-2007-0048</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-0045">CVE-2007-0045</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2564">CVE-2009-2564</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2981">CVE-2009-2981</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2982">CVE-2009-2982</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2983">CVE-2009-2983</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2986">CVE-2009-2986</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3431">CVE-2009-3431</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3461">CVE-2009-3461</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3462">CVE-2009-3462</a>  </td></tr>  </table> <br /><br />  <h2 class="title">Threat Remediation</h2><br /> <p>Fortinet provides coverage on Adobe vulnerabilities in October 2009.</p>  <table class="threats"> <tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2979">CVE-2009-2979</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.metadata.xml.buffer.overflow.html">Adobe.Reader.Metadata.XML.Buffer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2980">CVE-2009-2980</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.xobject.image.integer.overflow.html">Adobe.Reader.Xobject.Image.Integer.Overflow</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2985">CVE-2009-2985</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.font.cff.index.memory.corruption.html">Adobe.Reader.Font.CFF.Index.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2987">CVE-2009-2987</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.activex.control.dos.html">Adobe.Acrobat.ActiveX.Control.DoS</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2988">CVE-2009-2988</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.js.collab.dos.html">Adobe.Acrobat.JS.Collab.DoS</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2990">CVE-2009-2990</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.u3d.progressive.mesh.block.code.execution.html">Adobe.Reader.U3D.Progressive.Mesh.Block.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2991">CVE-2009-2991</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.firefox.plugin.rce.code.execution.html">Adobe.Acrobat.Firefox.Plugin.RCE.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2994">CVE-2009-2994</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.jpeg2000.qcc.memory.corruption.html">Adobe.JPEG2000.QCC.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2996">CVE-2009-2996</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.js.collab.memory.corruption.html">Adobe.Acrobat.JS.Collab.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2997">CVE-2009-2997</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.acrobat.u3d.line.set.heap.corruption.html">Adobe.Acrobat.U3D.Line.Set.Heap.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2998">CVE-2009-2998</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.u3d.mesh.declaration.memory.corruption.html">Adobe.Reader.U3D.Mesh.Declaration.Memory.Corruption</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3458">CVE-2009-3458</a></td><td><a1 href="/encyclopedia/vulnerability/adobe.reader.u3d.progressive.mesh.block.code.execution.html">Adobe.Reader.U3D.Progressive.Mesh.Block.Code.Execution</a1></td></tr> 	<tr><td align="center"><a href="http://www.cve.mitre.org/]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-38.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-38.html</guid>
		<pubDate>Wed, 14 Oct 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for October 2009</title>
		<description>
		<![CDATA[<br> The table below lists the Microsoft vulnerabilities for October.<br />  <table class="threats"> <tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-050.mspx">MS09-050</a></td><td>Vulnerabilities in SMBv2 Could Allow Remote Code Execution (975517)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2526">CVE-2009-2526</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2532">CVE-2009-2532</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3103">CVE-2009-3103</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-051.mspx">MS09-051</a></td><td>Vulnerabilities in Windows Media Runtime Could Allow Remote Code Execution (975682)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0555">CVE-2009-0555</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2525">CVE-2009-2525</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-052.mspx">MS09-052</a></td><td>Vulnerability in Windows Media Player Could Allow Remote Code Execution (974112)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2527">CVE-2009-2527</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-053.mspx">MS09-053</a></td><td>Vulnerabilities in FTP Service for Internet Information Services Could Allow Remote Code Execution (975254)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2521">CVE-2009-2521</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-3023">CVE-2009-3023</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-054.mspx">MS09-054</a></td><td>Cumulative Security Update for Internet Explorer (974455)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows,Internet Explorer</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1547">CVE-2009-1547</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2529">CVE-2009-2529</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2530">CVE-2009-2530</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2531">CVE-2009-2531</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-055.mspx">MS09-055</a></td><td>Cumulative Security Update of ActiveX Kill Bits (973525)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2493">CVE-2009-2493</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-056.mspx">MS09-056</a></td><td>Vulnerabilities in Windows CryptoAPI Could Allow Spoofing (974571)</td><td align="center">Important</td><td align="center">Spoofing</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2510">CVE-2009-2510</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2511">CVE-2009-2511</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-057.mspx">MS09-057</a></td><td>Vulnerability in Indexing Service Could Allow Remote Code Execution (969059)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2507">CVE-2009-2507</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-058.mspx">MS09-058</a></td><td>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (971486)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2515">CVE-2009-2515</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2516">CVE-2009-2516</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2517">CVE-2009-2517</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-059.mspx">MS09-059</a></td><td>Vulnerability in Local Security Authority Subsystem Service Could Allow Denial of Service (975467)</td><td align="center">Important</td><td align="center">Denial of Service</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2524">CVE-2009-2524</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-060.mspx">MS09-060</a></td><td>Vulnerabilities in Microsoft Active Template Library (ATL)) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0901">CVE-2009-0901</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2493">CVE-2009-2493</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2495">CVE-2009-2495</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-061.mspx">MS09-061</a></td><td>Vulnerabilities in the Microsoft .NET Common Language Runtime Could Allow Remote Code Execution (974378)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Microsoft .NET Framework, Microsoft Silverlight</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0090">CVE-2009-0090</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0091">CVE-2009-0091</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2497">CVE-2009-2497</a>  </td></tr> 	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-062.mspx">MS09-062</a></td><td>Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows,I]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-36.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-36.html</guid>
		<pubDate>Tue, 13 Oct 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Multiple Vulnerabilities in Adobe Acrobat / Reader</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet discovers multiple vulnerabilities in Adobe Reader / Acrobat which may allow a remote attacker to compromise a system.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution / Denial of Service (DoS).<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><ul><li>Adobe Reader 9.1.3 and earlier versions for Windows, Macintosh and UNIX</li><li>Adobe Acrobat 9.1.3 and earlier versions for Windows and Macintosh </li></ul><br /><b>Additional Information:</b><br /><br />Four vulnerabilities were discovered in Adobe Reader / Acrobat, each of which are highlighted below:<ul><li>FG-VD-09-015: Memory corruption vulnerability in Javascript implementation (CVE-2009-3460)</li><li>FG-VD-09-017: Denial of service through an ActiveX control specific to the OS, in "AcroPDF.DLL" (CVE-2009-2987)</li><li>FG-VD-09-018: Denial of service through an input validation issue in "annots.api" (CVE-2009-2988)</li><li>FG-VD-09-023: Memory corruption vulnerability in Javascript implementation (CVE-2009-2996)</li></ul><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Adobe (<a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">APSB09-15</a>). </li><li>The FortiGuard Global Security Research Team released a signature "<a href="http://www.fortiguard.com/encyclopedia/vulnerability/adobe.acrobat.js.collab.memory.corruption.html">Adobe.Acrobat.JS.Collab.Memory.Corruption</a>", which covers a vulnerability listed in CVE-2009-2996. </li><li>The FortiGuard Global Security Research Team released a signature "<a href="http://www.fortiguard.com/encyclopedia/vulnerability/adobe.acrobat.activex.control.dos.html">Adobe.Acrobat.ActiveX.Control.DoS</a>", which covers a vulnerability listed in CVE-2009-2987. </li><li>The FortiGuard Global Security Research Team released a signature "<a href="http://www.fortiguard.com/encyclopedia/vulnerability/adobe.acrobat.js.collab.dos.html">Adobe.Acrobat.JS.Collab.DoS</a>", which covers a vulnerability listed in CVE-2009-2988. </li><li>The FortiGuard Global Security Research Team released a signature "<a href="http://www.fortiguard.com/encyclopedia/vulnerability/adobe.acrobat.javascript.heap.allocation.memory.corruption.html">Adobe.Acrobat.Javascript.Heap.Allocation.Memory.Corruption</a>", which covers a vulnerability listed in CVE-2009-3460. </li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against these vulnerabilities. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">http://www.adobe.com/support/security/bulletins/apsb09-15.html</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3460">CVE-2009-3460</a> (FG-VD-09-015)</li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2987">CVE-2009-2987</a> (FG-VD-09-017)</li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2988">CVE-2009-2988</a> (FG-VD-09-018)</li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2996">CVE-2009-2996</a> (FG-VD-09-023)</li></ul><b>Acknowledgment:</b><br /><ul><li>Zhenhua Liu and XiaoPeng Zhang of Fortinet's FortiGuard Global Security Research Team</li><ul> <li>For Discovering: CVE-2009-2987, CVE-2009-2988, CVE-2009-2996</li></ul><li>Haifei Li of Fortinet's FortiGuard Global Security Research Team</li><ul><li>For Discovering: CVE-2009-3460</li></ul> </ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-37.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-37.html</guid>
		<pubDate>Tue, 13 Oct 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Reader Remote Code Execution Vulnerability (APSB09-15)</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Global Security Research Team investigates a vulnerability in Adobe Reader. <br><br><b>Impact:</b><br><br>Remote Code Execution.<br><br><b>Affected Software:</b><br><br>For a full list of affected software, please refer to the Adobe security advisory below. <br><br><b>Solutions:</b><br><ul><li>The FortiGuard Global Security Research Team released a signature "<a href="Adobe.Reader.Decode.Color.Remote.Code">Adobe.Reader.Decode.Color.Remote.Code</a>", which covers this specific vulnerability.</li><li>The FortiGuard Global Security Research Team released a signature "W32/Protux.GK!exploit", which covers a malicious PDF exploiting this vulnerability in the wild. </li><li>The FortiGuard Global Security Research Team released a signature "W32/Protux.GK!tr", which covers a trojan dropped by the malicious PDF. </li></ul>The FortiGuard Global Security Research Team continues to monitor attacks against this vulnerability.<br><br>Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this remote code execution vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br><br><b>References:</b><br><ul><li>Adobe Security Advisory: <a href="http://www.adobe.com/support/security/bulletins/apsb09-15.html">http://www.adobe.com/support/security/bulletins/apsb09-15.html</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3459">CVE-2009-3459</a></li></ul><br>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-35.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-35.html</guid>
		<pubDate>Thu, 08 Oct 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - September 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period August 21st - September 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions</a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Threat Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>13.1</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">HTTP.URI.Overflow</td><td>11.8</td><td><b>Critical</b></td>        </tr>	<tr>		<td>3</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>5.3</td><td>High</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.Windows.ASN.1.Bitstring.Overflow</td><td>4.2</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">FTP.Bounce.Attack</td><td>1.7</td><td>High</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">PNG.Image.Integer.Overflow</td><td>1.6</td><td><b>Critical</b></td>        </tr>	<tr>		<td>7</td><td class="left">Trojan.Storm.Worm.HTTP.DoS</td><td>1.6</td><td>Low</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">IKE.Exchange.DoS.Version</td><td>1.4</td><td>Low</td>        </tr>	<tr>		<td>9</td><td class="left">NaviCOPA.URI.Buffer.Overflow</td><td>1.1</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.Excel.Malformed.OBJECT.Type.File.Code.Execution</td><td>1.1</td><td>High</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape0909/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0909/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by detected exploit attempts</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 108 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 46 were reported to be actively exploited (42.6%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0909/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0909/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left"> W32/OnlineGames.BBR!tr</td><td>29.4</td><td>-</td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Bredo.G!tr</td><td>12.8</td><td><b>new</b></td>        </tr>	<tr><td>3</td><td class="left">JS/PackRedir.A!tr.dldr</td><td>3.7</td><td><b>+2</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>3.6</td><td><b>+2</b></td>        </tr>	<tr><td>5</td><td class="left">Adware/AdClicker</td><td>3.1</td><td><b>+2</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/Virut.A</td><td>2.9</td><td>-2</td>        </tr>	<tr><td>7</td><td class="left">W32/Netsky!similar</td><td>2.7</td><td><b>+1</b></td>        </tr>        <tr class="odd"><td>8</td><td class="left">HTML/Iframe_CID!exploit</td><td>2.3</td><td><b>+1</b></td>        </tr>	<tr><td>9</td><td class="left">W32/OnlineGames.DRP!tr.pws</td><td>2.0</td><td><b>+3</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/OnlineGames.EEX!tr</td><td>1.7</td><td><b>+12</b></td>        </tr> </table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0909/image-02.png"><img align=middle src="h]]>
		</description>
		<link>http://www.fortiguard.com/reports/roundup_september_2009.html</link>
		<guid>http://www.fortiguard.com/reports/roundup_september_2009.html</guid>
		<pubDate>Thu, 24 Sep 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Server Message Block Remote Code Execution Vulnerability (SMB2)</title>
		<description>
		<![CDATA[<b>Summary:</b><br><br>Fortinet's FortiGuard Global Security Research Team investigates a vulnerability in Microsoft's Server Message Block implementation (SMB2).<br><br><b>Impact:</b><br><br>Remote Code Execution.<br><br><b>Affected Software:</b><br><ul><li>Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2</li><li>Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2</li><li>Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2</li><li>Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2</li><li>Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2</li></ul><br><b>Solutions:</b><br><ul><li>The FortiGuard Global Security Research Team released a signature "<a href="http://www.fortiguard.com/encyclopedia/vulnerability/ms.smb2.negotiation.handler.code.execution.html">MS.SMB2.Negotiation.Handler.Code.Execution</a>", which covers this specific vulnerability.</li><li>Apply the suggested workaround <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">from Microsoft</a>.</li></ul><br>The FortiGuard Global Security Research Team continues to monitor attacks against this vulnerability.<br><br>Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this remote code execution vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br><br><b>References:</b><br><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">http://www.microsoft.com/technet/security/advisory/975497.mspx</a></li><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3103">CVE-2009-3103</a></li></ul><br>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-34.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-34.html</guid>
		<pubDate>Wed, 09 Sep 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for September 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for September.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-045.mspx">MS09-045</a></td><td>Vulnerability in JScript Scripting Engine Could Allow Remote Code Execution (971961)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1132">CVE-2009-1132</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-046.mspx">MS09-046</a></td><td>Vulnerability in DHTML Editing Component ActiveX Control Could Allow Remote Code Execution (956844)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2519">CVE-2009-2519</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-047.mspx">MS09-047</a></td><td>Vulnerabilities in Windows Media Format Could Allow Remote Code Execution (973812)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2498">CVE-2009-2498</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2499">CVE-2009-2499</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-048.mspx">MS09-048</a></td><td>Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (967723)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4609">CVE-2008-4609</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1925">CVE-2009-1925</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1926">CVE-2009-1926</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-049.mspx">MS09-049</a></td><td>Vulnerability in Wireless LAN AutoConfig Service Could Allow Remote Code Execution (970710)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1132">CVE-2009-1132</a>  </td></tr></table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in September 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1132">CVE-2009-1132</a></td><td><a1 href="/encyclopedia/vulnerability/ms.jscript.keyword.override.code.execution.html">MS.JScript.Keyword.Override.Code.Execution</a1></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2519">CVE-2009-2519</a></td><td><a1 href="/encyclopedia/vulnerability/ms.dhtml.editing.component.activex.control.code.execution.html">MS.DHTML.Editing.Component.ActiveX.Control.Code.Execution</a1></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2498">CVE-2009-2498</a></td><td><a1 href="/encyclopedia/vulnerability/ms.windows.asf.invalid.free.code.execution.html">MS.Windows.ASF.Invalid.Free.Code.Execution</a1></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2499">CVE-2009-2499</a></td><td><a1 href="/encyclopedia/vulnerability/ms.media.mp3.memory.corruption.html">MS.Media.MP3.Memory.Corruption</a1></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1926">CVE-2009-1926</a></td><td><a1 href="/encyclopedia/vulnerability/tcp.window.size.zero.dos.html">TCP.Window.Size.Zero.DoS</a1></td></tr></table><br />For more information on new and enhanced signatures, visit the <a href="/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="/contactus.html">Contact Us</a> web page.<br /><br /><br /><h2 class="title">Document History</h2><br /><table class="threats"><tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr><tr><td align="center">Tuesday, September 8, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr></table><br /><br /><b>Reference:</b><br /><ul><li>Microsoft Security Bulletin Summary for September 2009: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-sep.mspx</a></li></ul>]]>
		</description>
		<link>http://www.fortiguard.com/advisory/FGA-2009-33.html</link>
		<guid>http://www.fortiguard.com/advisory/FGA-2009-33.html</guid>
		<pubDate>Tue, 08 Sep 2009 00:00:00 -0800</pubDate>
	</item>
</channel>
</rss>
