Palo Alto Networks™, the network security company, today announced that its Threat Research Team has discovered two vulnerabilities in today's Microsoft Patch Tuesday security bulletin both of which could allow for remote code execution using Microsoft Office graphics filters. Microsoft credited Palo Alto Networks' Threat Research Team with finding CVE-2010-3945 (CGM Image Converter Buffer Overrun Vulnerability) and CVE-2010-3946 (PICT Image Converter Integer Overflow Vulnerability), which are each categorized as important.
The first of two vulnerabilities – CGM Image Converter Buffer Overrun Vulnerability - CVE-2010-3945 – is a remote code execution vulnerability that exists in the way that Microsoft Office allocates buffer size when handling CGM image files. The vulnerability could allow remote code execution if a user opens an Office document containing a specially crafted CGM image. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
The second one – PICT Image Converter Integer Overflow Vulnerability - CVE-2010-3946
– is also a remote code execution vulnerability affecting Microsoft Office. The vulnerability is in the way Microsoft Office allocates buffer size when handling PICT image files and can allow remote code execution if a user opens an Office document containing a specially crafted PICT image. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
The Palo Alto Networks Threat Research Team is active in the research community, aggressively pursuing both new vulnerability research and alleviation of all types of threats. The team has leveraged its expertise to uncover a string of critical and important vulnerabilities and have then worked with Microsoft to make sure users are protected.
Enterprises using legacy security technology increasingly lack visibility into and control of application traffic. Palo Alto Networks' next-generation firewalls are unique in the industry in their ability to see and control applications, users and content – not just ports, IP addresses and packets. Palo Alto Networks' next-generation firewalls enable enterprises to create granular, business-relevant security policies and safely control applications instead of the block-or-nothing approach offered by traditional port-blocking firewalls.
About Palo Alto Networks
Palo Alto Networks™ (paloaltonetworks.com) is the network security company. Its next-generation firewalls enable unprecedented visibility and granular policy control of applications and content – by user, not just IP address – at up to 10Gbps with no performance degradation. Based on patent-pending App-ID™ technology, Palo Alto Networks firewalls accurately identify and control applications – regardless of port, protocol, evasive tactic or SSL encryption – and scan content to stop threats and prevent data leakage. Enterprises can for the first time embrace Web 2.0 and maintain complete visibility and control, while significantly reducing total cost of ownership through device consolidation.
Palo Alto Networks, "The Network Security Company," the Palo Alto Networks Logo and App-ID are trademarks of Palo Alto Networks, Inc. in the United States. All other trademarks, trade names or service marks used or mentioned herein belong to their respective owners.