<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>
<title>FGCenter - Latest Threats, Advisories, Reports and News</title>
<link>http://www.fortiguardcenter.com/</link>

<language>en</language>
<copyright>Copyright 2009 Fortinet Inc. All Rights Reserved</copyright>
<pubDate>Fri, 03 Jul 2009 11:29:54 -0800</pubDate>
	<item>
		<title>Threatscape Report - June 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period May 21st - June 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Web Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.Windows.MSDTC.Heap.Overflow</td><td>13.3</td><td>Medium</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.SQL.Server.Empty.Passwor</td><td>10.0</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>6.9</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">SSLv3.SessionID.Overflow</td><td>5.5</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">HTTP.URI.Overflow</td><td>4.7</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.Windows.NAT.Helper.DNS.Query.DoS</td><td>4.5</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.Exchange.Mail.Calender.Buffer.Overflow</td><td>3.5</td><td>High</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>2.6</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">MS.Windows.Messenger.Service.Buffer.Overflow</td><td>1.4</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">FTP_bounce_attack</td><td>1.2</td><td>High</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape0609/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0609/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by detected exploit attempts</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 108 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 62 were reported to be actively exploited (57.4%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0609/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0609/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left"> W32/OnlineGames.BBR!tr</td><td>14.3</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Zbot.M!tr.pws</td><td>11.4</td><td><b>+55</b></td>        </tr>	<tr><td>3</td><td class="left">W32/Zbot.V!tr.pws</td><td>7.5</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">W32/Virut.A</td><td>7.5</td><td>-2</td>        </tr>	<tr><td>5</td><td class="left">JS/PackRedir.A!tr.dldr</td><td>4.2</td><td><b>+36</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>3.2</td><td>-3</td>        </tr>	<tr><td>7</td><td class="left">Adware/AdClicker</td><td>2.9</td><td>-2</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/FraudLoad.EPB!tr</td><td>2.8</td><td><b>new</b></td>        </tr>	<tr><td>9</td><td class="left">W32/Dloadr.CMV!tr</td><td>2.6</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/Dropper.PTD!tr</td><td>2.6</td><td>-9</td>        </tr> </table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0609/image-02.png"><img align=middle src="http://www.fortiguardcenter.com]]>
		</description>
		<link>http://www.fortiguardcenter.com/reports/roundup_june_2009.html</link>
		<guid>http://www.fortiguardcenter.com/reports/roundup_june_2009.html</guid>
		<pubDate>Tue, 30 Jun 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Memory Corruption Vulnerability in Adobe Reader / Acrobat</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />A memory corruption vulnerability exists when processing PDF documents and handling TrueType fonts, which could allow an attacker to execute arbitrary code with the privileges of the current user.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of product versions affected, please see the Adobe Security Bulletin reference below. <br /><br /><b>Additional Information:</b><br /><br />A crash will sometimes occur when processing a TrueType font within the document, leading to memory corruption and allowing the execution of remote code.<br /><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Adobe (<a href="http://www.adobe.com/support/security/bulletins/apsb09-07.html">APSB09-07</a>).</li><li># The FortiGuard Global Security Research Team released the IPS signature "Adobe.Reader.Acrobat.TrueType.Font.Handling.Memory.Corruption", which covers this specific vulnerability.</li></ul><br /> Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Adobe Security Bulletin: <a href="http://www.adobe.com/support/security/bulletins/apsb09-07.html">APSB09-07</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1857">2009-1857</a></a></li></ul><b>Acknowledgment:</b><br /><ul><li>Haifei Li of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-25.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-25.html</guid>
		<pubDate>Wed, 10 Jun 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Memory Corruption Vulnerability in Apple Safari</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />A memory corruption vulnerability exists in Apple Safari which allows a remote attacker to execute arbitrary code through a malicious webpage.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of product versions affected, please see the Apple Security Update reference below.<br /><br /><b>Additional Information:</b><br /><br />The memory corruption vulnerability occurs when handling HTML table elements. A remote attacker may craft a malicious webpage and lure an unsuspecting user. When the page is viewed and these elements are processed, arbitrary code execution may occur resulting in the victims machine being compromised.<br /><br /><b>Solutions:</b><br /><ul><li>Apple security updates are available via their Software Update mechanism</li><li>Apple security updates are available for manual download <a href="http://www.apple.com/support/downloads/">here</a>.</li><li>The FortiGuard Global Security Research Team released a signature "DHTML.Malicious.Table.Elements", which covers this specific vulnerability.</li></ul><br /> Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Apple Security Updates for Safari 4: <a href="http://support.apple.com/kb/HT3613">http://support.apple.com/kb/HT3613</a></li> <li>Apple Security Update for iPhone / iPod Touch: <a href="http://support.apple.com/kb/HT3318">http://support.apple.com/kb/HT3318</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4231">CVE-2008-4231</a></li></ul><b>Acknowledgment:</b><br /><ul><li>Haifei Li of Fortinet's FortiGuard Global Security Research Team </li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-23.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-23.html</guid>
		<pubDate>Tue, 09 Jun 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Memory Corruption Vulnerability in Microsoft's Internet Explorer</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />A memory corruption vulnerability exists in the DHTML handling of Microsoft's Internet Explorer which allows a remote attacker to compromise a system through a malicious site.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Bulletin reference below.<br /><br /><b>Additional Information:</b><br /><br />The vulnerability occurs when Internet Explorer processes special DHTML functions. A crash may happen when destroying a window after making a sequence of calls on the "tr" element. These calls are linked to the insertion, deletion and attributes of a table cell. The crash may then allow the arbitrary execution of code on the browsers machine.<br /><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Microsoft (MS09-019). </li><li>The FortiGuard Global Security Research Team released a signature "MS.IE.DHTML.Function.Remote.Code.Execution", which covers this specific vulnerability.</li></ul><br /> Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-019.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-019.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1141">CVE-2009-1141</a></li></ul><b>Acknowledgment:</b><br /><ul><li>Haifei Li of Fortinet's FortiGuard Global Security Research Team </li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-22.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-22.html</guid>
		<pubDate>Tue, 09 Jun 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for June 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for June.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-018.mspx">MS09-018</a></td><td>Vulnerabilities in Active Directory Could Allow Remote Code Execution (971055)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1138">2009-1138</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1139">2009-1139</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-022.mspx">MS09-022</a></td><td>Vulnerabilities in Windows Print Spooler Could Allow Remote Code Execution (961501)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0228">2009-0228</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0229">2009-0229</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0230">2009-0230</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-019.mspx">MS09-019</a></td><td>Cumulative Security Update for Internet Explorer (969897)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Internet Explorer</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3091">2007-3091</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1140">2009-1140</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1141">2009-1141</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1528">2009-1528</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1529">2009-1529</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1530">2009-1530</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1531">2009-1531</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1532">2009-1532</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-027.mspx">MS09-027</a></td><td>Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (969514)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0563">2009-0563</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0565">2009-0565</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-021.mspx">MS09-021</a></td><td>Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (969462)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0549">2009-0549</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0557">2009-0557</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0558">2009-0558</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0559">2009-0559</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0560">2009-0560</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0561">2009-0561</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1134">2009-1134</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-024.mspx">MS09-024</a></td><td>Vulnerability in Microsoft Works Converters Could Allow Remote Code Execution (957632)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1533">2009-1533</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx">MS09-026</a></td><td>Vulnerability in RPC Could Allow Elevation of Privilege (970238)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0568">2009-0568</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-025.mspx">MS09-025</a></td><td>Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (968537)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1123">2009-1123</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1124">2009-1124</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1125">2009-1125</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1126">2009-1126</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-020.mspx">MS09-020</a></td><td>Vulnerabilities in Internet Information Services (IIS) Could Allow Elevation of Privilege (970483)</td><td align="center">Important</td><td align="center">Elevation of Privilege</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1122">2009-1122</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1535">2009-1535</a>  </td></tr>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-023.mspx">MS09-023</a></td><td>Vulnerability in Windows Search Could Allow Information Disclosure (963093)</td><td align="center">Moderate</td><td align="center">Information Disclosure</td><td>Microsoft Windows</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0239">2009-0239</a>  </td></tr></table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in June 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2007-3091">CVE-2007-3091</a></td><td><a href="/ids/VID14732">MS.IE.Javascript.Cross.Domain.Information.Disclosure</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0228">CVE-2009-0228</a></td><td><a href="/ids/VID17496">MS.Windows.Print.Spooler.Buffer.Overflow</a></td></tr>	<tr><td align="center"><a href=]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-24.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-24.html</guid>
		<pubDate>Tue, 09 Jun 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Multiple Memory Corruption Vulnerabilities in Microsoft Office Excel</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Three memory corruption vulnerabilities exist in Microsoft Office Excel which allows a remote attacker to compromise a system through a malicious document.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Risk:</b><br /><br />Critical.<br /><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Bulletin reference below.<br /><br /><b>Additional Information:</b><br /><br />All the three vulnerabilities lies in "excel.exe", which is used when processing an Excel file. A maliciously crafted document may contain a malformed 1) BRAI(0x1051) record or 2)Object (0x5d) record or 3)Formula record (0x06) that when processed, will result in memory corruption and allow a remote attacker to arbitrarily execute code on the victims machine.<br /><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Microsoft (MS09-021). </li><li>The FortiGuard Global Security Research Team released signatures "MS.Excel.Record.Pointer.Code.Execution" and "MS.Excel.Field.Sanitization.Memory.Corruption, which cover the specific vulnerability. </li></ul><br /> Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-021.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-021.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0549">CVE-2009-0549</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0557">CVE-2009-0557</a>, <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0560">CVE-2009-0560</a></li></ul><b>Acknowledgment:</b><br /><ul><li>Bing Liu of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-21.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-21.html</guid>
		<pubDate>Tue, 09 Jun 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft DirectShow Remote Code Execution Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team investigates a vulnerability in Microsoft DirectX (DirectShow) through a specially crafted QuickTime media file.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution.<br /><br /><b>Affected Software:</b><br /><ul><li>DirectX 7.0 on Microsoft Windows 2000 Service Pack 4</li><li>DirectX 8.1 on Microsoft Windows 2000 Service Pack 4</li><li>DirectX 9.0 on Microsoft Windows 2000 Service Pack 4</li><li>DirectX 9.0 on Windows XP Service Pack 2 and Windows XP Service Pack 3</li><li>DirectX 9.0 on Windows XP Professional x64 Edition Service Pack 2</li><li>DirectX 9.0 on Windows Server 2003 Service Pack 2</li><li>DirectX 9.0 on Windows Server 2003 x64 Edition Service Pack 2</li><li>DirectX 9.0 on Windows Server 2003 with SP2 for Itanium-based Systems</li></ul><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released a signature "MS.DirectShow.NULL.Byte.Overwrite", which covers this specific vulnerability.</li></ul><br />The FortiGuard Global Security Research Team continues to monitor attacks against this vulnerability.<br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this remote code execution vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/971778.mspx">http://www.microsoft.com/technet/security/advisory/971778.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1537">CVE-2009-1537</a></li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-20.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-20.html</guid>
		<pubDate>Fri, 29 May 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - May 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period April 21st - May 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Web Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>8.2</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>2</td><td class="left">SSLv3.SessionID.Overflow</td><td>6.8</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">MS.Windows.NAT.Helper.DNS.Query.DoS</td><td>5.9</td><td>High</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.Windows.MSDTC.Heap.Overflow</td><td>5.9</td><td>Medium</td>        </tr>	<tr>		<td>5</td><td class="left">MS.Exchange.Mail.Calender.Buffer.Overflow</td><td>4.2</td><td>High</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>3.7</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.SQL.Server.Empty.Password</td><td>3.0</td><td>High</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">MS.IE.HTML.Attribute.Buffer.Overflow</td><td>2.1</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">Multiple.Vendor.ICMP.Remote.DoS</td><td>1.7</td><td>Low</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.Windows.ASN.1.Bitstring.Overflow</td><td>1.6</td><td>High</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape0509/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0509/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by detected exploit attempts</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 140 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 65 were reported to be actively exploited (46.4%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0509/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0509/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/Dropper.PTD!tr</td><td>34.5</td><td><b>+1</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Virut.A</td><td>7.7</td><td>-1</td>        </tr>	<tr><td>3</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>4.2</td><td><b>+3</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">W32/Netsky!similar</td><td>3.2</td><td><b>+3</b></td>        </tr>	<tr><td>5</td><td class="left">Adware/AdClicker</td><td>3.2</td><td><b>+4</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">HTML/Iframe_CID!exploit</td><td>3.0</td><td><b>+2</b></td>        </tr>	<tr><td>7</td><td class="left">W32/PackWaledac.B</td><td>2.8</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/MyTob.fam@mm</td><td>1.7</td><td><b>+2</b></td>        </tr>	<tr><td>9</td><td class="left">W32/Delf.AYO!tr</td><td>1.2</td><td><b>+6</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/Virut.E</td><td>1.1</td><td><b>+27</b></td>        </tr> </table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0509/image-02.png"><img align=middle src="http://www.fortigua]]>
		</description>
		<link>http://www.fortiguardcenter.com/reports/roundup_may_2009.html</link>
		<guid>http://www.fortiguardcenter.com/reports/roundup_may_2009.html</guid>
		<pubDate>Tue, 26 May 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Internet Information Services (IIS) Elevation of Privilege Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team investigates an elevation of privilege vulnerability in Microsoft Internet Information Services (IIS).<br /><br /><b>Impact:</b><br /><br />Elevation of privilege.<br /><br /><b>Affected Software:</b><br /><ul><li>Microsoft Internet Information Services 5.0<li>Microsoft Internet Information Services 5.1<li>Microsoft Internet Information Services 6.0</ul><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released a signature "<a href="http://www.fortiguardcenter.com/vulnency/VID17445">MS.IIS.WebDAV.Authentication.Bypass</a>", which covers this specific vulnerability.</li></ul><br />The FortiGuard Global Security Research Team continues to monitor attacks against this vulnerability.<br /><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this elevation of privilege vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Security Advisory: <a href="http://www.microsoft.com/technet/security/advisory/971492.mspx">http://www.microsoft.com/technet/security/advisory/971492.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1535">CVE-2009-1535</a></li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-19.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-19.html</guid>
		<pubDate>Tue, 19 May 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for May 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for May.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th>	<tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx">MS09-017</a></td><td>Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0220">2009-0220</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0221">2009-0221</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0222">2009-0222</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0223">2009-0223</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0224">2009-0224</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0225">2009-0225</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0226">2009-0226</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0227">2009-0227</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0556">2009-0556</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1128">2009-1128</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1129">2009-1129</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1130">2009-1130</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1131">2009-1131</a>  <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1137">2009-1137</a>  </td></tr></table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in May 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0220">CVE-2009-0220</a></td><td><a1 href="/ids/VID17434">MS.PowerPoint.PP4X322.DLL.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0221">CVE-2009-0221</a></td><td><a1 href="/ids/VID17435">MS.PowerPoint.Atom.Integer.Overflow</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0222">CVE-2009-0222</a></td><td><a1 href="/ids/VID17436">MS.PowerPoint.PP4X322.DLL.PackedData.Buffer.Overflow</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0223">CVE-2009-0223</a></td><td><a1 href="/ids/VID17437">MS.Powerpoint.Converter.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0224">CVE-2009-0224</a></td><td><a1 href="/ids/VID17440">MS.Powerpoint.Objects.Size.Heap.Overflow</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0225">CVE-2009-0225</a></td><td><a1 href="/ids/VID17442">MS.Powerpoint.Old.File.Format.Parsing.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0226">CVE-2009-0226</a></td><td><a1 href="/ids/VID17432">MS.PowerPoint.File.Format.Converter.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0227">CVE-2009-0227</a></td><td><a1 href="/ids/VID17438">MS.PowerPoint.File.Stack.Buffer.Overrun</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0556">CVE-2009-0556</a></td><td><a1 href="/ids/VID17362">MS.PowerPoint.OutlineTextRefAtom.Memory.Corruption</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1128">CVE-2009-1128</a></td><td><a1 href="/ids/VID17439">MS.PowerPoint.PSTSoundEntity.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1129">CVE-2009-1129</a></td><td><a1 href="/ids/VID17441">MS.PowerPoint.PSTExEmbed.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1130">CVE-2009-1130</a></td><td><a1 href="/ids/VID17443">MS.PowerPoint.HashCode10.Code.Execution</a></td></tr>	<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1131">CVE-2009-1131</a></td><td><a1 href="/ids/VID17430">MS.PowerPoint.CurrentUserAtom.Remote.Code.Execution</a></td></tr></table><br />For more information on new and enhanced signatures, visit the <a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>. If you require more information, contact the FortiGuard Team using our <a href="http://www.fortiguardcenter.com/contactus.php">Contact Us</a> web page.<br /><br /><br /><h2 class="title">Document History</h2><br /><table class="threats"><tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr><tr><td align="center">Tuesday, May 12, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr></table><br /><br /><b>Reference:</b><br /><ul><li>Microsoft Security Bulletin Summary for May 2009: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-may.mspx</a></li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-18.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-18.html</guid>
		<pubDate>Tue, 12 May 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - April 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period March 21st - April 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Web Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">SSLv3.SessionID.Overflow</td><td>9.3</td><td>High</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">SMS.SQL.Server.Empty.Password</td><td>8.4</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>5.5</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>4.6</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">MS.IE.HTML.Attribute.Buffer.Overflow</td><td>4.0</td><td>High</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.Windows.NAT.Helper.DNS.Query.DoS</td><td>3.7</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.Windows.ASN.1.Bitstring.Overflow</td><td>1.4</td><td>High</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">FTP.Bounce.Attack</td><td>1.2</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">LPD.Command.Buffer.Overflow</td><td>1.0</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">Oracle.sys.pbsde.init.Buffer.Overflow</td><td>0.9</td><td>Medium</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape0409/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0409/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by detected exploit attempts</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 96 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 30 were reported to be actively exploited (31.3%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0409/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0409/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/Virut.A</td><td>8.2</td><td>-</td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Dropper.PTD!tr</td><td>6.2</td><td><b>new</b></td>        </tr>	<tr><td>3</td><td class="left">W32/OnlineGames.MIG!tr.pws</td><td>5.7</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">Spy/OnLineGames</td><td>5.6</td><td><b>+1</b></td>        </tr>	<tr><td>5</td><td class="left">W32/Agent.JNR!tr</td><td>4.8</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>6</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>4.8</td><td>-3</td>        </tr>	<tr><td>7</td><td class="left">W32/Netsky!similar</td><td>4.2</td><td>-5</td>        </tr>        <tr class="odd"><td>8</td><td class="left">HTML/Iframe_CID!exploit</td><td>3.8</td><td>-4</td>        </tr>	<tr><td>9</td><td class="left">Adware/AdClicker</td><td>3.0</td><td><b>new</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/MyTob.fam@mm</td><td>2.8</td><td>-3</td>        </tr> </table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0409/image-02.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape040]]>
		</description>
		<link>http://www.fortiguardcenter.com/reports/roundup_apr_2009.html</link>
		<guid>http://www.fortiguardcenter.com/reports/roundup_apr_2009.html</guid>
		<pubDate>Thu, 23 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Multiple Vulnerabilities In HP StorageWorks Storage Mirroring</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team Discovers 3 Vulnerabilities in HP StorageWorks Storage Mirroring.<br /><br /><b>Impact:</b><br /><br />Remote Code Execution, Unauthorized Access, Denial of Service (DoS). <br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br />For a list of product versions affected, please see the HP advisory below.<br /><br /><b>Additional Information:</b><br /><br /><ul><li>A heap-based buffer overflow vulnerability exists in the HP StorageWorks Storage Mirroring Auto-Discovery Module that can lead to remote code execution. This is due to invalid bounds checking. Attackers can exploit this vulnerability by sending a malformed UDP packet.</li><li>A denial of service vulnerability exists in the HP StorageWorks Storage Mirroring Management Console. Attackers can exploit this vulnerability by sending a malformed UDP packet to port 1100 where the HP StorageWorks Storage Mirroring Management Console listens.</li><li>A weak password encryption algorithm is used in the HP StorageWorks Storage Mirroring Log-on Module. Attackers can easily acquire the password in cleartext.</li></ul><br /><b>Solutions:</b><br /><ul><li>Use the solution <a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01707538">provided by HP</a>.</li><li>The FortiGuard Global Security Research Team released the signature "<a href="http://www.fortiguardcenter.com/ids/VID17350">HP.StorageWorks.Storage.Mirroring.Auto.Discovery.Heap.Overflow</a>".  </li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this buffer overflow vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br /><br /><b>References:</b><br /><ul><li>HP's Advisory: <a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01707538">http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01707538</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0716">CVE-2009-0716</a><li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0717">CVE-2009-0717</a><li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0718">CVE-2009-0718</a><li></ul><b>Acknowledgement:</b><br /><ul><li>Zhenhua Liu, Junfeng Jia, and Xiaopeng Zhang of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-17.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-17.html</guid>
		<pubDate>Tue, 21 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Office Excel Memory Corruption Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team Discovers Memory Corruption Vulnerability in Microsoft Office Excel.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Bulletin reference below.<br /><br /><b>Additional Information:</b><br /><br />The vulnerability lies in "excel.exe", which is used when processing an Excel file. A maliciously crafted document will cause Excel to crash when processing. The crash occurs while calculating memory using an offset and a two-byte value contained in the document. If the two-byte value is set to a high value, an overflow condition will occur during memory calculation. A remote attacker can potentially control the memory referenced as a result of the overflow to alter program flow, and execute arbitrary code on a victims machine.<br /><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-009.mspx">MS09-009</a>).</li><li>The FortiGuard Global Security Research Team released a signature "MS.Excel.OBJ.Subrecord.Code.Execution", which covers this specific vulnerability.</li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-009.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-009.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0100">CVE-2009-0100</a><li></ul><b>Acknowledgement:</b><br /><ul><li>Haifei Li of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-16.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-16.html</guid>
		<pubDate>Tue, 14 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for April 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for April 2009.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-009.mspx">MS09-009</a></td>	<td>Vulnerabilities in Microsoft Office Excel Could Cause Remote Code Execution (968557)</td>	<td align="center">Critical</td>	<td align="center">Remote Code Execution</td>	<td>Microsoft Office</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0100">CVE-2009-0100</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-010.mspx">MS09-010</a></td>	<td>Vulnerabilities in WordPad and Office Text Converters Could Allow Remote Code Execution (960477)</td>	<td align="center">Critical</td>	<td align="center">Remote Code Execution</td>	<td>Microsoft Windows, Microsoft Office</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4841">CVE-2008-4841</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0087">CVE-2009-0087</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0088">CVE-2009-0088</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0235">CVE-2009-0235</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-011.mspx">MS09-011</a></td>	<td>Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (961373)</td>	<td align="center">Critical</td>	<td align="center">Remote Code Execution</td>	<td>Microsoft Windows</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0084">CVE-2009-0084</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-012.mspx">MS09-012</a></td>	<td>Vulnerabilities in Windows Could Allow Elevation of Privilege (959454)</td>	<td align="center">Important</td>	<td align="center">Elevation of Privilege</td>	<td>Microsoft Windows</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1436">CVE-2008-1436</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0078">CVE-2009-0078</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0079">CVE-2009-0079</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0080">CVE-2009-0080</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-013.mspx">MS09-013</a></td>	<td>Vulnerabilities in Windows HTTP Services Could Allow Remote Code Execution (960803)</td>	<td align="center">Critical</td>	<td align="center">Remote Code Execution</td>	<td>Microsoft Windows</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0086">CVE-2009-0086</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0089">CVE-2009-0089</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0550">CVE-2009-0550</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx">MS09-014</a></td>	<td>Cumulative Security Update for Internet Explorer (963027)</td>	<td align="center">Critical</td>	<td align="center">Remote Code Execution</td>	<td>Microsoft Windows, Internet Explorer</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2540">CVE-2008-2540</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0550">CVE-2009-0550</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0551">CVE-2009-0551</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0552">CVE-2009-0552</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0553">CVE-2009-0553</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0554">CVE-2009-0554</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-015.mspx">MS09-015</a></td>	<td>Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)</td>	<td align="center">Moderate</td>	<td align="center">Elevation of Privilege</td>	<td>Microsoft Windows</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2540">CVE-2008-2540</a>	</td></tr><tr>	<td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-016.mspx">MS09-016</a></td>	<td>Vulnerabilities in Microsoft ISA Server and Forefront Threat Management Gateway (Medium Business Edition) Could Cause Denial of Service (961759)</td>	<td align="center">Important</td>	<td align="center">Denial of Service</td>	<td>Microsoft Forefront Edge Security</td>	<td>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0077">CVE-2009-0077</a>		<a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0237">CVE-2009-0237</a>	</td></tr></table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in April 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-1436">CVE-2008-1436</a></td><td><a href="/ids/VID15558">          ASPXSpy.Detection                                          </a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2540">CVE-2008-2540</a></td><td><a href="/ids/VID15633">          Apple.Safari.Windows.Platform.Arbitrary.File.Download      </a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4841">CVE-2008-4841</a></td><td><a href="/ids/VID16768">          MS.Windows.WordPad.Converter.Code.Execution                </a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0077">CVE-2009-0077</a></td><td>                                  MS.ISA.Server.Forefront.Threat.Management.Gateway.DoS      </td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0078">CVE-2009-0078</a></td><td><a href="/ids/VID15558">          ASPXSpy.Detection                                          </a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0079">CVE-2009-0079</a></td><td><a href="/ids/VID15558">          ASPXSpy.Detection                                          </a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?n]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-14.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-14.html</guid>
		<pubDate>Tue, 14 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft WordPad and Office Text Converter Memory Corruption Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team Discovers Memory Corruption Vulnerability in Microsoft WordPad and Office Text Converter.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br />For a list of operating system and product versions affected, please see the Microsoft Bulletin reference below.<br /><br /><b>Additional Information:</b><br /><br />A maliciously crafted ".doc" file will cause WordPad or Word to crash when processing. A remote attacker can potentially control the program flow, and execute arbitrary code on a victims machine.<br /><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-010.mspx">MS09-010</a>).</li><li>The FortiGuard Global Security Research Team released a signature "MS.Wordpad.Office.Text.Converter.Memory.Corruption", which covers this specific vulnerability.</li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>Microsoft Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-010.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-010.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0087">CVE-2009-0087</a><li></ul><b>Acknowledgement:</b><br /><ul><li>Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-15.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-15.html</guid>
		<pubDate>Tue, 14 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>EMC RepliStor Buffer Overflow Vulnerability </title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team has discovered a buffer overflow vulnerability in EMC RepliStor.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><b>Affected Software:</b><br /><ul><li>EMC RepliStor 6.2 SP4 and earlier</li><li>EMC RepliStor 6.3 SP1 and earlier</li></ul><b>Additional Information:</b><br /><br />A remote, unauthenticated user may connect over TCP to the "ctrlservice.exe" or "rep_srv.exe" process and send a specially-crafted message to cause a heap based buffer overflow, which can result in arbitrary code execution.<br /><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released the signature "EMC.RepliStor.Integer.Overflow"</li><li>Users should use EMC's Powerlink solution to upgrade to the following EMC RepliStor products:<ul><li>RepliStor 6.2 SP5: Navigate in Powerlink to Home > Support > Software Downloads and Licensing > Downloads P-R >RepliStor 6.2 SP5</li><li>RepliStor 6.3 SP2: Navigate in Powerlink to Home > Support > Software Downloads and Licensing > Downloads P-R >RepliStor 6.3 SP2</li></ul></li></ul>Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this buffer overflow vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br /><br /><b>References:</b><br /><ul><li>EMC Powerlink: <a href="http://powerlink.emc.com/">powerlink.emc.com</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1119">CVE-2009-1119</a></li></ul><b>Acknowledgment:</b><br /><ul><li>Xiaopeng Zhang and Zhenhua Liu of Fortinet's FortiGuard Global Security Research Team </li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-13.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-13.html</guid>
		<pubDate>Wed, 08 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft PowerPoint Invalid Object Remote Code Execution Vulnerability (969136)</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />A maliciously crafted Microsoft PowerPoint file may lead to execution of arbitrary code when opened by a potential victim.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br /><ul><li>Microsoft Office PowerPoint 2000 Service Pack 3</li><li>Microsoft Office PowerPoint 2002 Service Pack 3</li><li>Microsoft Office PowerPoint 2003 Service Pack 3</li><li>Microsoft Office 2004 for Mac</li></ul><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released the IPS signature "MS.PowerPoint.OutlineTextRefAtom.Memory.Corruption", which covers this specific vulnerability.</li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this invalid object vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br /><br /><b>References:</b><br /><ul><li>CVE ID: <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0556">CVE-2009-0556</a></li><li>Microsoft Security Advisory (<a href="http://www.microsoft.com/technet/security/advisory/969136.mspx">969136</a>)</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-12.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-12.html</guid>
		<pubDate>Fri, 03 Apr 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - March 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period February 21st - March 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Web Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">Trojan.Storm.Worm.Krackin.Detection</td><td>62.6</td><td>High</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">SSLv3.SessionID.Overflow </td><td>3.1</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">Oracle.sys.pbsde.init.Buffer.Overflow</td><td>2.2</td><td>Medium</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>2.0</td><td><b>Critical</b></td>        </tr>	<tr>		<td>5</td><td class="left">MS.IIS.Web.Application.SourceCode.Disclosure</td><td>2.0</td><td>Medium</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">MS.Exchange.Mail.Calender.Buffer.Overflow</td><td>1.6</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.IE.HTML.Attribute.Buffer.Overflow</td><td>1.3</td><td>High</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>1.3</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">MS.Windows.NAT.Helper.DNS.Query.DoS </td><td>1.0</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.CMM.ICC.Profile.Buffer.Overflow</td><td>0.8</td><td>High</td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape0309/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0309/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by detected exploit attempts</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 85 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 14 were reported to be actively exploited (16.5%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0309/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0309/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>   	<tr><td>1</td><td class="left">W32/Virut.A</td><td>9.2</td><td><b>+1</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Netsky!similar</td><td>8.3</td><td>-1</td>        </tr>	<tr><td>3</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>7.9</td><td><b>+1</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left"> HTML/Iframe_CID!exploit</td><td>7.5</td><td>-1</td>        </tr>	<tr><td>5</td><td class="left">Spy/OnLineGames </td><td>6.6</td><td>-</td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/MyTob.FR@mm</td><td>3.1</td><td><b>+7</b></td>        </tr>	<tr><td>7</td><td class="left">W32/MyTob.fam@mm</td><td>2.6</td><td>-1</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/Delf.AYO!tr</td><td>2.5</td><td><b>+8</b></td>        </tr>	<tr><td>9</td><td class="left">Adware/Bdsearch</td><td>1.9</td><td><b>+10</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/Basine.C!tr.dldr</td><td>1.6</td><td>-1</td>        </tr> </table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0309/image-02.png"><img align=middle src="http://ww]]>
		</description>
		<link>http://www.fortiguardcenter.com/reports/roundup_mar_2009.html</link>
		<guid>http://www.fortiguardcenter.com/reports/roundup_mar_2009.html</guid>
		<pubDate>Fri, 27 Mar 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Apple iTunes DAAP Message Handling Denial of Service Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />A DoS vulnerability exists in Apple iTunes through a maliciously crafted DAAP message.<br /><br /><b>Impact:</b><br /><br />Denial of service.<br /><br /><b>Risk:</b><br /><ul><li>Medium</li></ul><br /><b>Affected Software:</b><br /><ul><li>Apple iTunes 8 for Windows, other versions may be affected</li><li>This issue does not affect Mac OS X systems</li></ul><br /><b>References:</b><br /><ul><li>Apple Security Bulletin: <a href="http://support.apple.com/kb/HT3487">http://support.apple.com/kb/HT3487</a></li><li>Apple Security Updates: <a href="http://support.apple.com/kb/ht1222">http://support.apple.com/kb/ht1222</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0016">CVE-2009-0016</a></li></ul><br /><b>Acknowledgement:</b><br /><ul><li>Xiaopeng Zhang, Zhenhua Liu, and Junfeng Jia of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-11.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-11.html</guid>
		<pubDate>Thu, 12 Mar 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for March 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for March 2009.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th><tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-006.mspx">MS09-006</a></td><td>Vulnerabilities in Windows Kernel Could Allow Remote Code Execution (958690)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0081">CVE-2009-0081</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0082">CVE-2009-0082</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0083">CVE-2009-0083</a> <tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-007.mspx">MS09-007</a></td><td>Vulnerability in SChannel Could Allow Spoofing (960225)</td><td align="center">Important</td><td align="center">Spoofing</td><td>Microsoft Windows</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0085">CVE-2009-0085</a> <tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-008.mspx">MS09-008</a></td><td>Vulnerabilities in DNS and WINS Server Could Allow Spoofing (962238)</td><td align="center">Important</td><td align="center">Spoofing</td><td>Microsoft Windows</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0093">CVE-2009-0093</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0094">CVE-2009-0094</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0233">CVE-2009-0233</a><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0234">CVE-2009-0234</a> </table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in March 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0081">CVE-2009-0081</a></td><td>MS.Kernel.GDI32.POLYLINE.Code.Execution</td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0082">CVE-2009-0082</a></td><td><i>local vulnerability</i></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0083">CVE-2009-0083</a></td><td><i>local vulnerability</i></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0093">CVE-2009-0093</a></td><td>MS.Windows.DNS.Server.WPAD.Registration.Spoofing</td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0094">CVE-2009-0094</a></td><td>MS.Windows.WINS.Server.WPAD.Registration.Spoofing<tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0233">CVE-2009-0233</a></td><td><i>covered by tuning the threshold of udp_dst_session in DoS sensor</i></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0234">CVE-2009-0234</a></td><td><i>covered by tuning the threshold of udp_dst_session in DoS sensor</i></td></tr></td></tr></table><br />For more information on new and enhanced signatures, visit the<a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>.If you require more information, contact the FortiGuard Team using our<a href="http://www.fortiguardcenter.com/contactus.php">Contact Us</a> web page.<br /><br /><br /><h2 class="title">Document History</h2><br /><table class="threats"><tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr><tr><td align="center">Tuesday, March 10, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr></table><br /><br /><b>Reference:</b><br /><ul>	<li>Microsoft Security Bulletin Summary for March 2009:	<a href="http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx">	http://www.microsoft.com/technet/security/bulletin/ms09-mar.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-10.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-10.html</guid>
		<pubDate>Tue, 10 Mar 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Adobe Reader / Acrobat Memory Corruption Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team protects against a memory corruption vulnerability in Adobe Reader / Acrobat.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br /><ul><li>Adobe Reader 9 and earlier versions</li><li>Adobe Acrobat Standard, Pro, and Pro Extended 9 and earlier versions</li></ul><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released the IPS signature "<a href="http://www.fortiguardcenter.com/vulnency/VID17271">Adobe.Reader.Acrobat.JBIG2.Stream.Index.Code.Execution</a>", which covers this specific vulnerability</li><li>Disable Javascript support in your PDF reader</li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this memory corruption vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br /><br /><b>References:</b><br /><ul><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0658">CVE-2009-0658</a></li><li>Adobe Security Bulletin: (<a href="http://www.adobe.com/support/security/advisories/apsa09-01.html">APS09-01</a>)</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-09.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-09.html</guid>
		<pubDate>Fri, 27 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - February 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period January 21st - February 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations & Regions<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate & Regions</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Web Traffic & Growth</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/worldmap-countries-small.png" width="321" height="132"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><br /><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations & Regions</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">Trojan.Storm.Worm.Krackin.Detection</td><td>62.7</td><td>High</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">MS.IIS.Web.Application.SourceCode.Disclosure</td><td>3.0</td><td>Medium</td>        </tr>	<tr>		<td>3</td><td class="left">SSLv3.SessionID.Overflow</td><td>2.2</td><td>High</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>2.0</td><td><b>Critical</b></td>        </tr>	<tr>		<td>5</td><td class="left">MS.Exchange.Mail.Calender.Buffer.Overflow</td><td>1.5</td><td>High</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">SSH.Client.Buffer.Overflow</td><td>1.2</td><td>High</td>        </tr>	<tr>		<td>7</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>1.2</td><td>High</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">MS.IE.HTML.Attribute.Buffer.Overflow </td><td>1.1</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">MS.Windows.NAT.Helper.DNS.Query.DoS</td><td>0.9</td><td>High</td>        </tr>        <tr class="odd">		<td>10</td><td class="left">Squid.NTLM.Authentication.Buffer.Overflow</td><td>0.5</td><td><b>Critical</b></td>        </tr></table><br /><br /><a href="http://www.fortiguardcenter.com/pics/threatscape0209/image-01a.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0209/image-01a.png" width="160" height="110"></a><br /><i>Figure 1a: Top 5 regions by detected exploit attempts</i></center><br /><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 117 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 30 were reported to be actively exploited (25.6%).</i><br /><br />Figure 1b breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0209/image-01b.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0209/image-01b.png" width="160" height="110"></a><br /><i>Figure 1b: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><br /><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>	<tr><td>1</td><td class="left">W32/Netsky!similar</td><td>9.3</td><td><b>+1</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Virut.A</td><td>7.8</td><td><b>+1</b></td>        </tr>	<tr><td>3</td><td class="left">HTML/Iframe_CID!exploit</td><td>7.8</td><td><b>+2</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>6.3</td><td>-</td>        </tr>	<tr><td>5</td><td class="left">Spy/OnLineGames </td><td>6.0</td><td>-4</td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/MyTob.fam@mm</td><td>3.5</td><td><b>+5</b></td>        </tr>	<tr><td>7</td><td class="left">W32/MyTob.BH.fam@mm</td><td>2.5</td><td>-</td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/PWS.Y!tr </td><td>2.2</td><td><b>+29</b></td>        </tr>	<tr><td>9</td><td class="left">W32/Basine.C!tr.dldr</td><td>2.1</td><td><b>+1</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/MyTob.AQ@mm</td><td>2.0</td><td>-1</td>        </tr></table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0209/image-02.png"><img align=middle src=]]>
		</description>
		<link>http://www.fortiguardcenter.com/reports/roundup_feb_2009.html</link>
		<guid>http://www.fortiguardcenter.com/reports/roundup_feb_2009.html</guid>
		<pubDate>Fri, 27 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Excel Invalid Object Remote Code Execution Vulnerability</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team protects against an invalid object error in Microsoft Excel. <br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br /><ul><li>Microsoft Office Excel 2000 Service Pack 3</li><li>Microsoft Office Excel 2002 Service Pack 3</li><li>Microsoft Office Excel 2003 Service Pack 3</li><li>Microsoft Office Excel 2007 Service Pack 1</li><li>Microsoft Office Excel Viewer 2003</li><li>Microsoft Office Excel Viewer 2003 Service Pack 3</li><li>Microsoft Office Excel Viewer</li><li>Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1</li><li>Microsoft Office 2004 for Mac</li><li>Microsoft Office 2008 for Mac</li><li>Open XML File Format Converter for Mac</li></ul><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released the IPS signature "<a href="http://www.fortiguardcenter.com/vulnency/VID17277">MS.Excel.SST.Extended.Unicode.Memory.Corruption</a>", which covers this specific vulnerability.</li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this invalid object vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br /><br /><b>References:</b><br /><ul><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0238">CVE-2009-0238</a><li><li>Bugtraq ID: <a href="http://www.securityfocus.com/bid/33870">33870</a><li><li>Microsoft Security Advisory (<a href="http://www.microsoft.com/technet/security/advisory/968272.mspx">968272</a>)<li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-08.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-08.html</guid>
		<pubDate>Thu, 26 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet Investigates a New SMS Mobile Worm: Yxes.A</title>
		<description>
		<![CDATA[The FortiGuard Global Security Research Team has investigated the case of a new mobile worm resorting to a breakthrough propagation strategy, which leverages SMS messages and Internet access.<br /><br />This new worm, deemed <a href="http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.A!worm">SymbOS/Yxes.A!worm</a> (also known as "Sexy View"), is targeting mobile devices running SymbianOS S60 3rd Edition (eg: Nokia 3250), but may run on a wider range of devices, as it has been reported to function on phones operating SymbianOS S60 3rd edition FP 1 (eg: Nokia N73). It bears a valid certificate signed by Symbian, and installs as a valid application on factory mobile devices running S60 3rd Edition.<br /><br />It gathers phone numbers from the infected device's file system, and repeatedly attempts to send SMS messages to those. The messages feature a malicious Web address (URL); upon "clicking" on the address in the received message, the recipients will download a copy of the worm (provided their phones/subscriptions allow for internet browsing).<br /><br />Beyond propagating to as many users as possible via the strategy mentioned above, the worm's aim is to gather intelligence on the infected victim (such as serial number of the phone, subscription number) and post it to a remote server likely controlled by cyber criminals. Whatever the latter may do with such information is unknown as of writing.<br /><br />It must be noted that due to its propagation strategy relying on the worm copy being hosted on a web server, the worm can mutate easily. According to Guillaume Lovet, senior manager of Fortinet's Threat Research Team, "As far as our analysis goes, the worm currently does not take commands from the remote servers it contacts. However, since the copies hosted on the malicious servers are controlled by the cyber criminals, they may update them whenever they want, thereby effectively mutating the worm, adding or removing functionality. We're really at the edge of a mobile botnet here."<br /><br />The Yxes mobile worm is reported to be currently spreading in the wild. It is recommended for mobile users to have a valid security solution in place, such as Fortinet's FortiClient Mobile, to protect against threats. Caution should always be taken when opening attachments and following URL's received through messages (SMS/MMS). In the case of an infection, please contact your service provider.<br /><br /><b>Update:</b><br /><br />Our investigation confirms that the worm executes on Nokia 3250 handsets, but again is likely not limited to this. Once installed, no program icon or related information could be found in the system menu. On launch, the worm executes as the process "EConServer.exe", which is likely meant to camouflage alongside the existing legitimate system process "EComServer.exe". The worm will also automatically run every time the device is rebooted / power cycled. Further, it bears a destructive nature and will kill certain processes such as the application manager (AppMgr). The following is a list of processes sought to destroy: AppMgr, TaskSpy, Y-Tasks, ActiveFile and TaskMan.<br /><br />Fortinet's FortiGuard Global Security Research Team protects against additional variants of SymbOS/Yxes.A, namely B, C, and D. Subscribers to Fortinet's FortiClient Mobile should be protected against these variants.<br /><br /><b>Action:</b><br /><ul><li>Fortinet's FortiGuard Antivirus Definitions protecting against Yxes have been available since February 8, 2009</li><li>Fortinet's FortiGuard Global Security Research Team collaborates with carriers to provide additional protection against mobile threats</li><li>Symbian's SDN has been notified</li><li>Registrars of domains hosting copies of the worm have been notified</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-07.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-07.html</guid>
		<pubDate>Wed, 18 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for February 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for February 2009.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th><tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx">MS09-002</a></td><td>Cumulative Security Update for Internet Explorer (961260)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows, Internet Explorer</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0075">CVE-2009-0075</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0076">CVE-2009-0076</a> <tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-003.mspx">MS09-003</a></td><td>Vulnerabilities in Microsoft Exchange Could Allow Remote Code Execution (959239)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Exchange Server</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0098">CVE-2009-0098</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0099">CVE-2009-0099</a> <tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-004.mspx">MS09-004</a></td><td>Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft SQL Server</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-5416">CVE-2008-5416</a> <tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-005.mspx">MS09-005</a></td><td>Vulnerabilities in Microsoft Office Visio Could Allow Remote Code Execution (957634)</td><td align="center">Important</td><td align="center">Remote Code Execution</td><td>Microsoft Office</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0095">CVE-2009-0095</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0096">CVE-2009-0096</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0097">CVE-2009-0097</a></table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in February 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0075">CVE-2009-0075</a></td><td>MS.IE7.Deleted.DOM.Object.Access.Memory.Corruption	</td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0076">CVE-2009-0076</a></td><td>MS.IE7.CSS.Style.Swithcing.Memory.Corruption	</td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0098">CVE-2009-0098</a></td><td>MS.Exchange.Server.TNEF.Code.Execution	</td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2009-0099">CVE-2009-0099</a></td><td>MS.Exchange.Server.Attendant.DoS	</td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-5416">CVE-2008-5416</a></td><td>MS.SQL.Server.Sp_replwritetovarbin.Memory.Overwrite	</td></tr></table><br />For more information on new and enhanced signatures, visit the<a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>.If you require more information, contact the FortiGuard Team using our<a href="http://www.fortiguardcenter.com/contactus.php">Contact Us</a> web page.<br /><br /><br /><h2 class="title">Document History</h2><br /><table class="threats"><tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr><tr><td align="center">Tuesday, February 10, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr></table><br /><br /><b>Reference:</b><br /><ul>	<li>Microsoft Security Bulletin Summary for February 2009:	<a href="http://www.microsoft.com/technet/security/bulletin/ms09-feb.mspx">	http://www.microsoft.com/technet/security/bulletin/ms09-feb.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-05.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-05.html</guid>
		<pubDate>Tue, 10 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Multiple vulnerabilities in Microsoft Office Visio</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Three memory corruption vulnerabilities lie in Microsoft Office Visio 2003, which allow a remote attacker to compromise a system through a malicious document.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br />For a list of operating systems and product versions affected, please see the Microsoft Security Bulletin reference below.<br /><br /><b>Solutions:</b><br /><ul><li>Use the solution provided by Microsoft (<a href="http://www.microsoft.com/technet/security/bulletin/ms09-005.mspx">MS09-005</a>).</li></ul><br /><b>References:</b><br /><ul><li>Microsoft Bulletin: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-005.mspx">http://www.microsoft.com/technet/security/bulletin/ms09-005.mspx</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0095">CVE-2009-0095</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0096">CVE-2009-0096</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0097">CVE-2009-0097</a></li></ul><br /><b>Acknowledgement:</b><br /><ul><li>Bing Liu of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-06.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-06.html</guid>
		<pubDate>Tue, 10 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet discovers multiple vulnerabilities in RealNetworks' RealPlayer</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team has discovered two vulnerabilities in RealPlayer, which allow a remote attacker to compromise a system through a malicious media clip.<br /><br /><b>Impact:</b><br /><br />Remote code execution.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><ul><li>RealNetworks RealPlayer 11</li></ul><br /><b>Additional Information:</b><br /><br />Internet Video Recording (IVR) files contain media content that is played and recorded by RealPlayer. A remote attacker could craft a malicious IVR file, that when sent to an unsuspecting user, may allow the execution of arbitrary code when viewed, using one of two vulnerabilities during RealPlayer's IVR processing routine:<ul><li>A heap corruption vulnerability that occurs when altering a field that determines the length of a structure</li><li>A vulnerability that allows an attacker to write one null byte to an arbitrary memory address by using an overly long file name length value</li></ul>It should be noted that the victim does not necessarily have to open the malicious file for exploitation to occur: the vulnerabilities lie in a DLL that is also used as a plugin for the Windows Explorer shell. A successful attack could take place by merely previewing the IVR file through Windows Explorer.<br /><br /><b>Solutions:</b><br /><ul><li>The FortiGuard Global Security Research Team released the signature "<a href="http://www.fortiguardcenter.com/ids/VID15756">RealNetworks.RealPlayer.IVR.File.Processing.Code.Execution</a>"</li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against these two vulnerabilities. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle. <br /><br /><b>References:</b><br /><ul><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0375">CVE-2009-0375</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0376">CVE-2009-0376</a></li></ul><br /><b>Acknowledgement:</b><br /><ul><li>Haifei Li of Fortinet's FortiGuard Global Security Research Team</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-04.html</guid>
		<pubDate>Thu, 05 Feb 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Threatscape Report - January 2009 Edition</title>
		<description>
		<![CDATA[The following statistics are compiled from Fortinet's FortiGate network security appliances and intelligence systems for the period December 21st, 2008 - January 20th, 2009.<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="50%" align="left"><h3 class="title">Table of Contents:</h3><ul><li>Exploits and Intrusion Prevention</li><ul>   <li><a href="#1" class="redlink">Top 10 Exploitations<a></li>   <li><a href="#2" class="redlink">New Vulnerability Coverage</a></li></ul><li>Malware Today</li><ul>   <li><a href="#3" class="redlink">Top 10 Variants</a></li>   <li><a href="#4" class="redlink">Regions & Volume</a></li></ul><li>Spam and Email Threats</li><ul>   <li><a href="#5" class="redlink">Spam Rate</a></li>   <li><a href="#6" class="redlink">Top 3 In The Wild</a></li></ul><li>Crawling the Web</li><ul>   <li><a href="#7" class="redlink">Web Traffic</a></li></ul><li><a href="#8" class="redlink">Activity Recap</a></li></ul></td><td width="50%"><center><img align=middle src="http://www.fortiguardcenter.com/images/FortiWorldMap3.jpg" width="428" height="176"><br /><i>FortiGuard Global Threat Research</i></center></td></tr></table><h2 class="title">Exploits and Intrusion Prevention</h2><br /><br /><a name="1"></a><h3 class="title"><u>Top 10 Exploitations</u></h3><br /><br />Top 10 exploitation attempts detected for this period, ranked by vulnerability traffic. Percentage indicates the portion of activity the vulnerability accounted for out of all attacks reported in this edition. Severity indicates the general risk factor involved with the exploitation of the vulnerability, rated from low to critical. Critical issues are outlined in bold:<br /><center><table class="threats" style="width:90%">	<tr>                <th>Rank</th><th>Vulnerability</th><th>Percentage</th><th>Severity</th>	</tr>	<tr>		<td>1</td><td class="left">Trojan.Storm.Worm.Krackin.Detection</td><td>44.1</td><td>High</td>        </tr>        <tr class="odd">		<td>2</td><td class="left">Danmec.Asprox.SQL.Injection </td><td>5.3</td><td>High</td>        </tr>	<tr>		<td>3</td><td class="left">MS.SQL.Server.Insert.Statements.Privilege.Elevation</td><td>3.8</td><td>High</td>        </tr>        <tr class="odd">		<td>4</td><td class="left">MS.Network.Share.Provider.Unchecked.Buffer.DoS </td><td>3.6</td><td>High</td>        </tr>	<tr>		<td>5</td><td class="left">MS.IIS.Web.Application.SourceCode.Disclosure</td><td>2.9</td><td>Medium</td>        </tr>        <tr class="odd">		<td>6</td><td class="left">TCP.PORT0</td><td>2.7</td><td>Low</td>        </tr>	<tr>		<td>7</td><td class="left">SSLv3.SessionID.Overflow</td><td>2.4</td><td>High</td>        </tr>        <tr class="odd">		<td>8</td><td class="left">HTTP.Server.Localhost.Request.Source.Code.Disclosure</td><td>1.5</td><td>High</td>        </tr>	<tr>		<td>9</td><td class="left">MS.DCERPC.NETAPI32.Buffer.Overflow</td><td>1.3</td><td><b>Critical</b></td>        </tr>        <tr class="odd">		<td>10</td><td class="left">MS.SMB.DCERPC.SRVSVC.PathCanonicalize.Overflow</td><td>1.0</td><td>High</td>        </tr></table></center><br /><a name="2"></a><h3 class="title"><u>New Vulnerability Coverage</u></h3><br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="75%" align="left" valign="top">There were a total of 43 vulnerabilities added to FortiGuard IPS coverage this period.<br/><i>Of these added vulnerabilities, 13 were reported to be actively exploited (30.2%).</i><br /><br />Figure 1 breaks down added vulnerabilities by severity, coverage and active exploitation in the wild. <br /><br />For more information, observe the detailed reports for this period at:<ul><li><a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">Intrusion Prevention - Service Update History</a></li></ul></td><td width="25%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0109/image-01.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0109/image-01.png" width="160" height="110"></a><br /><i>Figure 1: New vulnerability coverage for this edition, categorized by severity</i></center></td></tr></table><h2 class="title">Malware Today</h3><br /><br /><a name="3"></a><h3 class="title"><u>Top 10 Variants</u></h3><br /><br />Top 10 malware activity by individual variant. Percentage indicates the portion of activity the malware variant accounted for out of all malware threats reported in this edition. Top 100 shifts indicate positional changes compared to last edition's Top 100 ranking, with "new" highlighting the malware's debut in the Top 100. Figure 2 below shows the detected volume for the malware variants listed within the Top 5:<br /><br /><table cellpadding="0" cellspacing="0" width="100%" border="0"><tr width="100%" align="center" class"="tdBolgBgWhite"><td width="70%" align="left"><center><table class="threats">	<tr>                <th>Rank</th><th>Malware Variant</th><th>Percentage</th><th>Top 100 Shift</th>	</tr>	<tr><td>1</td><td class="left">Spy/OnLineGames</td><td>8.8</td><td><b>+2</b></td>        </tr>        <tr class="odd"><td>2</td><td class="left">W32/Netsky!similar</td><td>8.2</td><td>-</td>        </tr>	<tr><td>3</td><td class="left">W32/Virut.A</td><td>7.4</td><td><b>+3</b></td>        </tr>        <tr class="odd"><td>4</td><td class="left">HTML/Iframe.DN!tr.dldr</td><td>7.1</td><td><b>+1</b></td>        </tr>	<tr><td>5</td><td class="left">HTML/Iframe_CID!exploit</td><td>6.9</td><td>-1</td>        </tr>        <tr class="odd"><td>6</td><td class="left">W32/Dropper.VEM!tr</td><td>5.4</td><td><b>+94</b></td>        </tr>	<tr><td>7</td><td class="left">W32/MyTob.BH.fam@mm</td><td>3.7</td><td><b>+3</b></td>        </tr>        <tr class="odd"><td>8</td><td class="left">W32/Small.AACQ!tr.dldr</td><td>2.6</td><td>-1</td>        </tr>	<tr><td>9</td><td class="left">W32/MyTob.AQ@mm</td><td>2.1</td><td><b>+6</b></td>        </tr>        <tr class="odd"><td>10</td><td class="left">W32/Basine.C!tr.dldr</td><td>1.9</td><td>-2</td>        </tr></table></center></td><td width="30%"><center><a href="http://www.fortiguardcenter.com/pics/threatscape0109/image-02.png"><img align=middle src="http://www.fortiguardcenter.com/pics/threatscape0109/image-02.png" width="160" height="110"></a><br /><i>Figure 2: Activity curve for top five malware variants</i></center></td></tr></table><br /><br /><a name="4"></a><h3 class="title"><u>Regions & Volume</u></h3><br /><br />Top 5 regions for this period, ranked by disti]]>
		</description>
		<link>http://www.fortiguardcenter.com/reports/roundup_jan_2009.html</link>
		<guid>http://www.fortiguardcenter.com/reports/roundup_jan_2009.html</guid>
		<pubDate>Thu, 29 Jan 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Microsoft Security Bulletin for January 2009</title>
		<description>
		<![CDATA[The table below lists the Microsoft vulnerabilities for January 2009.<br /><table class="threats"><tr width="10%" align="center" class="tdBoldBgGray"><th>MS Bulletin Number </th><th width="33%">Microsoft Bulletin Title</th><th width="10%">Severity</th><th width="15%">Impact of Vulnerability</th><th width="20%">Affected Software</th><th width="12%">CVE ID</th><tr><td align="center"><a href="http://www.microsoft.com/technet/security/Bulletin/MS09-001.mspx">MS09-001</a></td><td>Vulnerabilities in SMB Could Allow Remote Code Execution (958687)</td><td align="center">Critical</td><td align="center">Remote Code Execution</td><td>Microsoft Windows</td><td><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4114">CVE-2008-4114</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4834">CVE-2008-4834</a> <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4835">CVE-2008-4835</a></table><br /><br /><h2 class="title">Threat Remediation</h2><br /><p>Fortinet provides coverage on Microsoft vulnerabilities in January 2009.</p><table class="threats"><tr align="center" class="tdBoldBgGray" width="30%"><th>CVE Number</th><th width="70%">Signature Name</th><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4114">CVE-2008-4114</a></td><td><a href="http://www.fortiguardcenter.com/ids/VID14194">SMB.Malformed.DataOffset</a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4834">CVE-2008-4834</a></td><td><a href="http://www.fortiguardcenter.com/ids/VID17134">MS.SMB.Trans.Request.NT.Create.Memory.Corruption</a></td></tr><tr><td align="center"><a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4835">CVE-2008-4835</a></td><td><a href="http://www.fortiguardcenter.com/ids/VID17135">MS.SMB.Trans2.Request.Memory.Corruption</a></td></tr></table><br />For more information on new and enhanced signatures, visit the<a href="http://www.fortiguardcenter.com/intrusionprevention/serviceUpdateHistory.html">IPS Service Update History</a>.If you require more information, contact the FortiGuard Team using our<a href="http://www.fortiguardcenter.com/contactus.php">Contact Us</a> web page.<br /><br /><br /><h2 class="title">Document History</h2><br /><table class="threats"><tr align="center" class="tdBoldBgGray"><th width="25%">Revision Date</th><th width="15%">Version Number</th><th width="60%"> </th></tr><tr><td align="center">Tuesday, January 13, 2009</td><td align="center">1</td><td>Initial Documentation.</td></tr><tr><td align="center">Tuesday, January 16, 2009</td><td align="center">2</td><td>Signatures have been released on IPS Definition 2.587 previously in beta state..</td></tr></table><br /><br /><b>Reference:</b><br /><ul>	<li>Microsoft Security Bulletin Summary for January 2009:	<a href="http://www.microsoft.com/technet/security/bulletin/ms09-jan.mspx">	http://www.microsoft.com/technet/security/bulletin/ms09-jan.mspx</a></li></ul> ]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-03.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-03.html</guid>
		<pubDate>Fri, 16 Jan 2009 00:00:00 -0800</pubDate>
	</item>
	<item>
		<title>Fortinet discovers multiple vulnerabilities in Oracle Secure Backup</title>
		<description>
		<![CDATA[<b>Summary:</b><br /><br />Fortinet's FortiGuard Global Security Research Team has discovered five vulnerabilities in Oracle Secure Backup.<br /><br /><b>Impact:</b><br /><br />Remote code execution and denial of service.<br /><br /><b>Risk:</b><br /><ul><li>Critical</li></ul><br /><b>Affected Software:</b><br /><br />Please refer to the <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html">Oracle Critical Patch Update Advisory</a> for affected versions of Oracle Secure Backup.<br /><br /><b>Additional Information:</b><br /><br /><i>By default, Oracle Secure Backup listens and receives NDMP protocol data on TCP port 10,000. The following four vulnerabilities pertain to the handling of this received NDMP data by process "obndmp.exe".</i> <br /><br />One buffer overflow vulnerability that can lead to remote code execution was discovered through Oracle Secure Backup: <ul><li>Sending a malformed NDMP client authentication packet will cause a overflow a buffer overflow due to invalid bounds checking </li></ul><br />Three denial of service vulnerabilities were discovered through Oracle Secure Backup by sending malformed data to various ports:<ul><li>Sending a malformed NDMP connect open packet will cause a crash</li><li>Sending a malformed NDMP connect close packet will cause a crash</li><li>Sending a malformed NDMP mover get state packet will cause a crash</li></ul><br /><i>By default, Oracle Secure Backup listens and receives private protocol data on TCP port 400. The following vulnerability pertains to the handling of this received data by process "observiced.exe".</i><br /><br />One denial of service vulnerability was discovered through Oracle Secure Backup:<ul><li>Sending some malformed private data will cause a null pointer dereference, leading to a crash</li></ul><br /><b>Solutions:</b><br /><ul><li>Users should apply available updates <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html">provided by Oracle</a></li><li>The FortiGuard Global Security Research Team released the signature "<a href="http://www.fortiguardcenter.com/ids/VID15751">Oracle.NDMP.CONNECT.CLIENT.AUTH.User.ID.Buffer.Overflow</a>" </li></ul><br />Fortinet customers who subscribe to Fortinet’s intrusion prevention (IPS) service should be protected against this buffer overflow vulnerability. Fortinet’s IPS service is one component of FortiGuard Subscription Services, which also offer comprehensive solutions such as antivirus, Web content filtering and antispam capabilities. These services enable protection against threats on both application and network layers. FortiGuard Services are continuously updated by the FortiGuard Global Security Research Team, which enables Fortinet to deliver a combination of multi-layered security intelligence and true zero-day protection from new and emerging threats. These updates are delivered to all FortiGate, FortiMail and FortiClient products. Fortinet strictly follows responsible disclosure guidelines to ensure optimum protection during a threat's lifecycle.<br /><br /><b>References:</b><br /><ul><li>Oracle Critical Patch Update Advisory: <a href="http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html">http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5441">CVE-2008-5441</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5442">CVE-2008-5442</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5443">CVE-2008-5443</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5444">CVE-2008-5444</a></li><li>CVE ID: <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5445">CVE-2008-5445</a></li></ul><br /><b>Acknowledgement:</b><br /><ul><li>Xiaopeng Zhang and Zhenhua Liu of Fortinet's FortiGuard Global Security Research Team </li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/advisory/FGA-2009-02.html</link>
		<guid>http://www.fortiguardcenter.com/advisory/FGA-2009-02.html</guid>
		<pubDate>Tue, 13 Jan 2009 00:00:00 -0800</pubDate>
	</item>
</channel>
</rss>
