Microsoft Active Template Library ActiveX Controls Multiple Vulnerabilities
16 Oct. 2009
Summary
This security update resolves several privately reported vulnerabilities in ActiveX Controls for Microsoft that were compiled with a vulnerable version of Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control.
Vulnerable Systems:
* Microsoft Office XP
* Microsoft Office 2003
* Microsoft Office 2007
* Microsoft Visio 2002 Viewer
* Microsoft Office Visio 2003 Viewer
* Microsoft Office Visio Viewer 2007
This security update is rated Critical for all supported editions of Microsoft Outlook 2002, Microsoft Office Outlook 2003, Microsoft Office Outlook 2007, Microsoft Visio 2002 Viewer, Microsoft Office Visio 2003 Viewer, and Microsoft Office Visio Viewer 2007.
The security update addresses the vulnerabilities by correcting the manner in which ATL handles the instantiation of objects from data streams, providing updated versions of the affected components and controls built using corrected ATL headers.