Security Advisory - October 12, 2010
Zscaler Provides Immediate Vulnerability Protection in the Face of Microsoft’s Largest Ever Patch Cycle
Zscaler, working with Microsoft through their MAPPs program, has proactively deployed protections for the following 16 web based, client-side vulnerabilities included in the October 2010 Microsoft security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the October release and deploy additional protections as necessary.
Severity: Critical
Affected Software
  • Internet Explorer 6
  • Internet Explorer 7
  • Internet Explorer 8
Description: An information disclosure vulnerability exists in the way that the toStaticHTML API sanitizes HTML, that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user. 
Description: An information disclosure vulnerability exists in the way that the toStaticHTML API sanitizes HTML that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user.
Description: An information disclosure vulnerability exists in the way that Internet Explorer processes CSS special characters.
Description: A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted.
Description: A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted.
Description: A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted when a document in an HTML format is opened in Microsoft Word.
Description: An information disclosure vulnerability exists in Internet Explorer that could allow script to gain access to information in another domain or Internet Explorer zone.
Description: A remote code execution vulnerability exists in the way that Internet Explorer accesses an object that has not been correctly initialized or has been deleted.
Severity: Critical
Affected Software
  • Microsoft  SharePoint Server
Description: An information disclosure vulnerability exists in the way that the toStaticHTML API sanitizes HTML, that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user. 
Description: An information disclosure vulnerability exists in the way that the toStaticHTML API sanitizes HTML, that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the logged-on user.
Severity: Critical
Affected Software
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Windows 7
Description: A remote code execution vulnerability exists in the way that Microsoft Windows Embedded OpenType (EOT) font technology parses certain tables in specially crafted embedded fonts.
Severity: Important
Affected Software
  • Windows XP
  • Windows Server 2003
Description: An elevation of privilege vulnerability exists in the way that the Windows OpenType Font (OTF) format driver improperly parses specially crafted OpenType fonts.
Description: An elevation of privilege vulnerability exists in the way that the Windows OpenType Font (OTF) format driver improperly validates specially crafted OpenType fonts.
Severity: Important
Affected Software
  • Microsoft Office XP
  • Microsoft Office 2003
  • Microsoft Office 2007
  • Microsoft Office 2010
  • Microsoft Office 2004 for Mac
  • Microsoft Office 2008 for Mac
Description: A remote code execution vulnerability exists in the way that Microsoft Word handles stack validation when parsing a specially crafted Word file.
Severity: Important
Affected Software
  • Microsoft Office XP
  • Microsoft Office 2003
  • Microsoft Office 2007
  • Microsoft Office 2004 for Mac
  • Microsoft Office 2008 for Mac
Description: A remote code execution vulnerability exists in the way that Microsoft Excel handles specially crafted Excel files.
Severity: Important
Affected Software
  • Windows XP
  • Windows Server 2003
  • Windows Server 2008
  • Windows Vista
  • Windows 7
Description: A remote code execution vulnerability exists in the way that the Windows Media Player deallocates objects during a reload operation via a Web browser.
About Zscaler
Through a multi-tenant, globally-deployed infrastructure, Zscaler enforces business policy, mitigates risk, and provides twice the functionality at a fraction of the cost of current solutions. It enables organizations to provide the right access to the right users, from any place and on any device, while empowering the end-user with a rich Internet experience. For more information, visit us at www.zscaler.com.
Press Contacts:
Paula Dunne
Office: +1-408-776-1400, Mobile: +1-408-893-8750
Paula.Dunne@zscaler.com
Zscaler®, and the Zscaler Logo are trademarks of Zscaler, Inc. in the United States. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners.
Related Links:
 
Lunch and
Learn Seminar

What Hackers Know That You Don't About iPads & Facebook
Live Webcast
Selecting the Right    Secure Web Gateway for a Mobile and
Social World
  Find us online    
 
[+] Zscaler Quick Links - Software as a Service - Secure Email and Web Gateway
© 2009-2012 Zscaler, Inc. All rights reserved. |  Privacy Policy | Acceptable Use Policy | Site Map