|
Brought to you by:
Suppliers of:
|
|
|
| |
| This security update resolves several privately reported vulnerabilities in ActiveX Controls for Microsoft that were compiled with a vulnerable version of Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control. |
| |
Credit:
The information has been provided by David Dewey, Ryan Smith and Microsoft.
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/ms09-060.mspx
|
| |
Vulnerable Systems:
* Microsoft Office XP
* Microsoft Office 2003
* Microsoft Office 2007
* Microsoft Visio 2002 Viewer
* Microsoft Office Visio 2003 Viewer
* Microsoft Office Visio Viewer 2007
This security update is rated Critical for all supported editions of Microsoft Outlook 2002, Microsoft Office Outlook 2003, Microsoft Office Outlook 2007, Microsoft Visio 2002 Viewer, Microsoft Office Visio 2003 Viewer, and Microsoft Office Visio Viewer 2007.
The security update addresses the vulnerabilities by correcting the manner in which ATL handles the instantiation of objects from data streams, providing updated versions of the affected components and controls built using corrected ATL headers.
CVE Information:
CVE-2009-0901
CVE-2009-2493
CVE-2009-2495
|
|
|
|
|