You are here

Fortinet Discovers Critical Vulnerability Affecting Multiple Microsoft Office Products

Microsoft Credits Fortinet's Security Research Team for Discovering Second Critical Vulnerability

SUNNYVALE, Calif., July 11, 2006 - Fortinet - the pioneer and leading provider of multi-threat security solutionstoday announced that its leading security research team was key in discovering the latest Microsoft™ critical vulnerability, MS06-039 (see also CVE-2006-0033), which impacts users of several Microsoft Office™ products. The vulnerability allows attackers, using a malformed Portable Network Graphics (PNG) file embedded in a Microsoft Office™ document, to gain complete control of a user's machine and/or run arbitrary commands. The vulnerability exists in the Portable Network Graphics import filter (PNG32.FLT) component that is included as part of many Microsoft Office™ products.

The vulnerability affects users of the following specific software:

  • Microsoft Office 2003 Service Pack 1
  • Microsoft Office 2003 Service Pack 2
  • Microsoft Project 2003
  • Microsoft OneNote 2003
  • Microsoft Office XP Service Pack 3
  • Microsoft Office 2000 Service Pack 3
  • Microsoft Project 2002
  • Microsoft Project 2000
  • Microsoft Works Suite 2004
  • Microsoft Works Suite 2005
  • Microsoft Works Suite 2006

Microsoft users should immediately apply the update provided by Microsoft on July 11, 2006. Fortinet's security research team was critical in discovering this vulnerability, as noted in the Microsoft Security Bulletin (http://www.microsoft.com/technet/security/bulletin/ms06-Jul.mspx).For more information on this vulnerability, please visit Fortinet's FortiGuard™ Center athttp://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-22.html.

FortiGuard Network Information
All FortiGate systems in production worldwide are kept up to date automatically by Fortinet's FortiGuardNetwork, which provides continuous updates that ensure protection against the latest threats around the clock and around the world. For more information on the FortiGuard Network visit:http://www.fortinet.com/FortiGuardCenter/

About Fortinet (www.fortinet.com)

Fortinet is the confirmed leader of Unified Threat Management market. The company's award-winning FortiGate™ series of ASIC-accelerated multi-threat security systems, winner of the 2004 Security Product of the Year Award from Network Computing Magazine and the 2003 Networking Industry Awards Firewall Product of the Year, are the new generation of real-time network protection systems. They detect and eliminate the most damaging, content-based threats from e-mail and Web traffic such as viruses, worms, intrusions, inappropriate Web content and more in real time - without degrading network performance. Fortinet's solutions are the only security products that are certified seven times over by the ICSA (firewall, antivirus, IPSec, SSL, IDS, client antivirus detection and cleaning), and deliver a full range of network-level and application-level services in integrated, easily managed platforms. Named a Light Reading Top 10 Private Company and #4 on Silicon Valley/San Jose Business Journal's "Fast 50" list, Fortinet is privately held and based in Sunnyvale, California.

 

How to Buy

Purchase Fortinet Products


Not only is the volume of email traffic rising but with it, the complexity of malware with the presence of blended threats combining spam, viruses, worms and spyware. To help ensure optimum service and security for our customers, we needed an effective multi-layered solution that combined antivirus, anti-spam and anti-spyware technologies in one appliance. FortiMail met our performance requirements while providing ease-of-use and management to our IT team which is essential as we do not have the time or resources to deploy and maintain separate point solutions.

Gunther Fischer
Head of Product and Service Enabler for the IT & Networks business unit
H3G Austria