Added on 29 Jul 2009(267 Views)
The out-of-band update scheduled for the 28th of July, the update that was meant to address a critical vulnerability in Internet Explorer and a moderate vulnerability in Visual Studios, has been rolled out to Microsoft customers. At the time, the Redmond-based company could not go into specifics, but now that the update has been released, it can provide a more in-depth details about the out-of-band update. Here’s a little hint: it’s Active Template Library (ATL).Here is precisely what Microsoft released the other day:
Security Advisory 973882, which provides info on Microsoft’s “ongoing investigation into vulnerabilities in the public and private versions of Microsoft's Active Template Library (ATL).”
Microsoft Security Bulletin MS09-034, which details a mitigation for Internet Explorer that will foil an attacker’s attempt to exploit components and controls built using Active Template Library. Multiple other unrelated IE vulnerabilities are addressed in the bulletin as well. MS09-034 applies to Internet Explorer 5.01, Internet Explorer 6 and Internet Explorer 6 Service Pack 1, Internet Explorer 7, and Internet Explorer 8
Microsoft Security Bulletin MS09-035, which details a moderate vulnerability in Visual Studio Active Template Library that if exploited by a person with malicious intent could allow the attacker to perform remote code execution. MS09-035 applies to Windows 2000 Service Pack 4, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. If you have applied MSO9-32, then you should be okay, explained Microsoft, adding that no active exploits taking advantage of the vulnerabilities presented in MS09-035 have been detected in the wild
So why did Microsoft push this out-of-band update? Jonathan Ness, Microsoft Security Research and Defense Engineering, provides an explanation.
“While the vulnerability has been known to Microsoft for some time, additional information regarding these vulnerabilities has been growing over the past few weeks. And with the Black Hat and Def Con security conference getting people together around the same watering hole, natural curiosity means that risk to customers could increase as more information is disclosed. We’ve seen one active attack on an ATL vulnerability targeting the msvidctl.dll control. We decided to proactively release these security updates to help protect customers and mitigate the risk in a more controlled manner. We believe the right thing to do is to help protect customers with out-of-band security updates in this unique situation where we anticipate the risk will increase before our next scheduled security update opportunity,” said Ness.
Don't forget to:
RSSTags: Microsoft, Patch, Security, Update, Patch Tuesday, Visual Studio, Internet Explorer, IE, ATL, Active Template Library
Link to this article:
Add comment:
Software News
This Week Only: One Opera Unite App per Day
Opera Software, the company behind the innovative Opera web browser has just announced the release of Opera 10.10 as a final, stable software application. That is good news for Opera users, but here comes one better...
23 Nov 2009
Reinvent the Web: Opera 10.10 Final with Opera Unite
Earlier this year Opera Software announced that it would “reinvent the web” – then on the 16th of June do this (reinvent the world I mean) with Opera Unite, a new technology that makes the old client-server computing model look outdated....
23 Nov 2009
Palm Delivers WebOS 1.3.1 to European Customers
Palm recently announced that it updated the WebOS (the operating system that powers the Palm Pre and the Palm Pixi) to version 1.3.1 and that it released it to its...
23 Nov 2009
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
Recommended Tools
Registry Booster 2010 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



