Home / bulletins

MS09-060 - Critical: Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965) - Version:1.5

Posted on 18 February 2010

Critical

Severity Rating: Critical - Revision Note: V1.5 (February 17, 2010): Corrected the MBSA detection entries for Microsoft Office Outlook 2007 and Microsoft Office Visio Viewer 2007. This is an information change only. There were no changes to the security update files or detection logic.Summary: This security update resolves several privately reported vulnerabilities in ActiveX Controls for Microsoft Office that were compiled with a vulnerable version of Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

Other versions

 

TOP