Interview

Sai Infosystems- Setting High Standards...

Sai Infosystems- Setting High Standards...

In an exclusive interaction with ITVar News, Ki
Read More >

READ All

Fortinet Discovers Microsoft Critical Vulnerability

Posted on June, Friday 15, 2007 By itVARnews Staff

Fortinet announced that its Fortinet Global Security Research Team was key in discovering one of the latest Microsoft critical vulnerabilities (CVE-2007-2222).


Fortinet – the pioneer and leading provider of unified threat management (UTM) solutions –announced that its Fortinet Global Security Research Team was key in discovering one of the latest Microsoft critical vulnerabilities (CVE-2007-2222), called the “Speech Control Memory Corruption Vulnerability,� which impacts users of Microsoft Speech.

The two remote buffer overflow vulnerabilities exist in the “xvoice.dll� ActiveX component of Microsoft Speech version 4.0a, which can allow an attacker to execute arbitrary code on the affected system by exploiting either vulnerability. This, in turn, allows an attacker to take full control of a victim’s system.

“Anything that allows the execution of arbitrary code from a remote source leaves a user open to cyber attackers exploiting and capitalizing on the vulnerability,� said Manager of Threat Research at Fortinet, Steve Fossen. “Users should always install all updates for the software they’re using and

protect their connected computers with threat mitigation solutions; otherwise they’re donating their resources to the hackers and spammers of the world.�

Microsoft Speech users should immediately apply the update provided by Microsoft on June 12, 2007. The Fortinet Global Security Team was critical in discovering these vulnerabilities, as noted in the Microsoft Security Bulletin.

Discuss this Story

 


 Add a Comment

Reload Image



"ITVAR News welcome comments that advance the story directly or with relevant information. We try to block comments that appear to be spam or use offensive language. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of IT VAR News or Techplus Media. We cannot be held responsible for error and authenticity of details associated with comments. IT VAR News does not endorse the products or its specifications."

 Comments