56910 : Microsoft Visual Studio Active Template Library (ATL) Header Mismatch Remote Code Execution
Printer | http://osvdb.org/56910 | Email This | Edit Vulnerability

Views This Week Views All Time Added to OSVDB Last Modified Modified (since 2008) Percent Complete
15 3191 over 2 years ago about 1 year ago 20 times 55%

This Entry needs help! It is only 55% Complete. Click the edit link above to add more information.

Contributing is fast and easy, and benefits the entire security community.

Timeline

Vendor Informed Date Vendor Ack Date Disclosure Date Vendor Solution Date
2008-12-05 2009-01-05 2009-08-11 2009-08-11
Time to Patch Time to Vendor Response
249 days 31 days

Description

<em style='font-weight:bold;'>(Description Provided by <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-2494" target="_blank">CVE</a>)</em> : The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka &quot;ATL Object Type Mismatch Vulnerability.&quot;

Classification

Location: Remote / Network Access
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Private, Exploit Commercial
Disclosure: Vendor Verified, Coordinated Disclosure

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Unknown or Incomplete

References

Tools & Filters

Snort

15638 15639
40556

Credit

CVSSv2 Score

CVSSv2 Base Score = 10.0
Source: nvd.nist.gov | Generated: 2009-08-13 | Disagree?

Access_vector_2 Access_complexity_2 Authentication_2 Confidentiality_impact_2 Integrity_impact_2 Availability_impact_2

Blogs

This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.

2009/09/26 22:05:27 | Bugs and Fixes: File-Sharing Vulnerability Hits VistaVista News1 ViewsDigg thisAdd on del.icio.us

from: VistaKnowledge.com

Windows Vista users (and IT folks taking care of Server 2008 computers) should watch out for a new security hole involving Windows file sharing. A remote attacker could assume full control of a vulnerable computer by exploiting a flaw in the SMB protocol for Windows file and printer sharing. Most home users should already have a firewall in place that blocks attempts to reach the ports that SMB uses (139 and 445). Microsoft may have a patch available by the time you read this, but as of this writing no fix was yet available.

2009/09/21 10:12:00 | Microsoft Security Releases ISO Image - Sep. 2009

from: Free Download 4Shared softwares |Rapidshare|Megaupload|Megashare and Symbian Software

Microsoft Security Releases ISO Image - Sep. 2009 | ISO | 700 MB This DVD5 ISO image file contains the security updates for Windows released on Windows Update on March 10th, 2009. The image does not contain security updates for other Microsoft products. This DVD5 ISO image is intended for administrators that need to download multiple individual language versions of each security update and that do not use an automated solution such as Windows Server Update Services (WSUS).

2009/09/08 18:14:00 | Microsoft Security Bulletins 08Sep09

from: Security Garden

Following is an overview of the five new security bulletins being released today, each identified as Critical and having a Vulnerability Impact identified as Remote Code Execution. Note that MS09-048and MS09-049 require a restart. The other updates may require a restart, depending upon what programs are open at the time of update. The best practice is to restart the computer after applying any updates.

2009/09/15 17:33:20 | [MS KBs] New KB Articles At Microsoft 15 Sep 2009 - Weekly Summary

from: Cliff Hobbs - FAQShop.com and Microsoft MVP ConfigMgr/ SMS

.NET Framework 2.0 973746 FIX: A System.Runtime.InteropServices.COMException exception occurs when you use COM components in the .NET Framework 2.0 to access form data or querystring data that contains a TAB character Outlook 2003 973515 Description of the Outlook 2003 Junk E-mail Filter update: September, 08, 2009 Outlook 2007 973514 Description of the Outlook 2007 Junk E-mail Filter update: September 08, 2009 SQL Server 2005 974068 FIX: Error message when an

2009/09/11 14:58:00 | Download Vista and XP Security Release ISO Image for September 2009

from: Tech-Talks.com

A total of five security bulletins designed to patch no less than eight vulnerabilities impacting various Windows releases was made available via Windows Update on September 8th, 2009. As it is customary, Microsoft also bundled the patches for security holes in Windows operating systems in a single package and made it available as a standalone download. Users are now able to grab the September 2009 Security Release ISO Image from the Microsoft Download Center.

2009/09/10 04:14:26 | MS09-037: Description of the security update for Microsoft HtmlInput Object ActiveX Control in Windows XP Media Center Edition, Windows Vista, and…

from: Microsoft Patch Watch

MS09-037: Description of the security update for Microsoft HtmlInput Object ActiveX Control in Windows XP Media Center Edition, Windows Vista, and… No tags for this post. Related postsNo related posts.

2009/08/12 21:45:49 | MS09-037: Description of the security update for the Active Template Library: August 11, 2009

from: Windows 2008 Security

Original post: MS09-037: Description of the security update for the Active Template Library: August 11, 2009

2009/08/12 21:45:32 | MS09-037: Description of the security update for Outlook Express: August 11, 2009

from: Windows 2008 Security

Here is the original:  MS09-037: Description of the security update for Outlook Express: August 11, 2009

2009/08/12 16:57:00 | So what are YOU doing tonight?

from: Windows 2008 Security

Microsoft August 2009 Black Tuesday Overview: http://isc.sans.org/diary.html?storyid=6937 The Microsoft Security Response Center (MSRC) : August 2009 Bulletin Release: http://blogs.technet.com/msrc/archive/2009/08/11/august-2009-bulletin-release.aspx Security Research & Defense : MS09-039: More information about the WINS security bulletin: http://blogs.technet.com/srd/archive/2009/08/11/ms09-039-more-information-about-the-wins-security-bulletin.aspx Security Research & Defense : MS09-037:

2009/08/25 17:52:33 | HP Microsoft MS 973540 XPe Add-on 1.00 Rev.A

from: Drivers Download

This package installs the fix from Microsoft Knowledge Base Article 973540 on the supported thin client models running a supported operating system. NOTE: For more information about this issue, see Microsoft Knowledge Base Article 973540, “MS09-037: Description of the security update for Windows Media Player.” PREREQUISITES: - Microsoft Windows XP Embedded (XPe) Operating System with Service Pack 2 (SP2) or Service Pack 3 (SP3), o… (read more) Link Driver DownloadT: 5 | B: 5 | S: 25.08.2009 -

2009/08/24 16:23:22 | HP Mobile Thin Client Image 2.1.136 Microsoft Critical Updates Package 1.1 REV:A

from: Drivers Download

This package contains all Microsoft Security Updates needed for the following Mobile Thin Client Images:HP 4410t Mobile Thin Client Microsoft Windows Standard (WES) Image 2.1.136PRODUCT MODEL(S):  HP 4410t Mobile Thin ClientENHANCEMENTS:  Adds the following Microsoft QFEs (listed by month).August ‘09- Microsoft QFE MS09-037 (KB973908) - For more information, see … (read more) Link Driver DownloadT: 1 | B: 1 | S: 01.01.1970 - 02:00

2009/08/20 08:40:00 | Microsoft Security Bulletin Minor Revisions - August 19, 2009

from: MSMVPS.COM

Issued: August 19, 2009 Summary The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details. * MS09-044 - Critical * MS09-037 - Critical * MS09-035 - Moderate Bulletin Information: * MS09-044 - Critical - http://www.microsoft.com/technet/security/bulletin/ms09-044.mspx - Reason for Revision: V1.2 (August 19, 2009): Corrected the registry key verification entry for RDP Version 5.1 on Windows XP Service Pack 2 (KB958470).

2009/08/19 14:19:55 | Notification of revised WSUSScn2.cab released on 08/17/2009

from: The WSUS Support Team Blog

On Monday the WU/MU team released a revised WSUSSCN2.CAB file. This new cab file addresses reported issues with last Tuesday’s release of the security bulletin MS09-037 being over-offered on x64 platform systems. No systems are left un-secure as a result of this problem but the updated CAB file corrects the reporting and offering errors. We recommend that .cab users download and run this newer version of the .cab file. Thanks, The WU/MU team

2009/08/18 14:11:00 | August 2009 Security Bulletin Webcast Video and Customer Q&A

from: The WSUS Support Team Blog

Looks like the folks on the MSRC blog just posted the August security bulleting webcast and customer Q&A.  To quote their site: It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers.

2009/08/17 13:44:26 | FYI: Re-offer reports confirmed for KB973869

from: Microsoft Patch Watch

I just wanted to let you know that the MU team has investigated some reports that the KB973869 (MS09-037) update is being re-offered through Automatic Updates and Windows Update on some x64 systems even after it has already been installed, and they identified some limited scenarios where this is occurring with Windows Server 2003 x64, Windows XP x64, and Windows Server 2003 for Itanium-based systems. For all the details see http://blogs.technet.com/wsus/archive/2009/08/14/re-offer-reports-confirmed-for-kb973869-ms09-037.aspx J.C.

2009/08/17 13:44:26 | FYI: Re-offer reports confirmed for KB973869

from: The WSUS Support Team Blog

I just wanted to let you know that the MU team has investigated some reports that the KB973869 (MS09-037) update is being re-offered through Automatic Updates and Windows Update on some x64 systems even after it has already been installed, and they identified some limited scenarios where this is occurring with Windows Server 2003 x64, Windows XP x64, and Windows Server 2003 for Itanium-based systems. For all the details see http://blogs.technet.com/wsus/archive/2009/08/14/re-offer-reports-confirmed-for-kb973869-ms09-037.aspx J.C.

2009/08/13 15:58:00 | Download Vista SP2 and XP SP3 Security Patches ISO Image for August 2009

from: Tech-Talks.com

On the heels of releasing the August 2009 security bulletins via Windows Update and as standalone downloads, Microsoft has also made available the patches targeting supported Windows releases packaged as an ISO image. Now, all administrators have the possibility to leverage automated solutions for patch deployment such as Windows Server Update Services (WSUS) in their environments, and the Security Release ISO Images come to streamline the process of integrating security updates.

2009/08/13 08:20:17 | Vista SP2 and XP SP3 Critical Updates

from: PC Tips Box

Posted on August 13th, 2009 by JasonMicrosoft released no less than eight security bulletins for the various supported releases of Windows client and server operating systems, including for the latest service packs of Windows Vista and Windows XP. Out of the total of patch packages impacting Windows, half feature a maximum severity rating of Critical, with the remaining four being rated as Important.

2009/08/13 08:20:00 | Microsoft Security Bulletin Minor Revisions - August 12, 2009

from: MSMVPS.COM

Issued: August 12, 2009 Summary The following bulletins have undergone a minor revision increment. Please see the appropriate bulletin for more details. * MS09-043 - Critical * MS09-042 - Important * MS09-039 - Critical * MS09-037 - Critical * MS09-035 - Moderate Bulletin Information: * MS09-043 - Critical - http://www.microsoft.com/technet/security/bulletin/ms09-043.mspx - Reason for Revision: V1.1 (August 12, 2009): Corrected the restart requirement for Visual

2009/08/25 19:26:53 | HP Microsoft MS 973815 XPe Add-On 1.00 Rev.A

from: Drivers Download

This package installs the fix from Microsoft Knowledge Base Article 973815 on the supported thin client models running a supported operating system. NOTE: For more information about this issue, see Microsoft Knowledge Base Article 973815, “MS09-037: Description of the security update for Microsoft MSWebDVD ActiveX Control in Windows XP and Windows Server 2003.” PREREQUISITES: - Microsoft Windows XP Embedded (XPe) Operating System … (read more) Link Driver DownloadT: 1 | B: 1 | S: 01.01.1970 -

Comments

No Comments.

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2012 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use