Home / bulletins

MS09-037 - Critical: Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908) - Version:2.1

Posted on 17 December 2009

Critical

Severity Rating: Critical - Revision Note: V2.1 (December 16, 2009): Added a link to Microsoft Knowledge Base Article 973908 under Known Issues in the Executive Summary.Summary: This security update resolves several privately reported vulnerabilities in Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control hosted on a malicious website. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

Other versions

 

TOP