Security Advisory - September 14, 2010
Zscaler Provides Protection for 3 New Microsoft Vulnerabilities
Zscaler, working with Microsoft through their MAPPs program, has proactively deployed protections for the following three web based, client-side vulnerabilities included in the September 2010 Microsoft security bulletins. Zscaler will continue to monitor exploits associated with all vulnerabilities in the September release and deploy additional protections as necessary.
Severity: Critical
Affected Software
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
Description: A remote code execution vulnerability exists in the way that the MPEG-4 codec handles supported format files. This vulnerability could allow code execution when a user opens a specially crafted media file.
Severity: Critical
Affected Software
  • Windows XP
  • Windows Server 2003
  • Windows Vista
  • Windows Server 2008
  • Microsoft Office XP
  • Microsoft Office 2003
  • Microsoft Office 2007
Description: A remote code execution vulnerability exists in affected versions of Microsoft Windows and Microsoft Office. The vulnerability exists because Windows and Office incorrectly parses specific font types, which could lead to remote code execution.
Severity: Important
Affected Software
  • Windows XP
  • Windows Server 2003
Description: A remote code execution vulnerability exists in the way that Microsoft WordPad processes memory when parsing a specially crafted Word 97 document. The vulnerability could allow remote code execution when a user opens a specially crafted Word file that includes a malformed structure.
About Zscaler
Through a multi-tenant, globally-deployed infrastructure, Zscaler enforces business policy, mitigates risk, and provides twice the functionality at a fraction of the cost of current solutions. It enables organizations to provide the right access to the right users, from any place and on any device, while empowering the end-user with a rich Internet experience. For more information, visit us at www.zscaler.com.
Press Contacts:
Paula Dunne
Office: +1-408-776-1400, Mobile: +1-408-893-8750
Paula.Dunne@zscaler.com
Zscaler®, and the Zscaler Logo are trademarks of Zscaler, Inc. in the United States. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners.
Related Links:
 
Lunch and
Learn Seminar

What Hackers Know That You Don't About iPads & Facebook
Live Webcast
Selecting the Right    Secure Web Gateway for a Mobile and
Social World
  Find us online    
 
[+] Zscaler Quick Links - Software as a Service - Secure Email and Web Gateway
© 2009-2012 Zscaler, Inc. All rights reserved. |  Privacy Policy | Acceptable Use Policy | Site Map