Home / bulletins MS09-060 - Critical: Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution (973965) - Version:1.4
Posted on 11 February 2010
There is an newer version: MS09-060 - Version: 1.5
CriticalSeverity Rating: Critical - Revision Note: V1.4 (February 9, 2010): Revised this bulletin to announce a detection logic change to fix the issue where the July 8, 2008 update for Outlook 2003 (KB953432) was incorrectly being offered in addition to the update package for Microsoft Office Outlook 2003 (KB973705). This is a deployment change only that does not affect the files contained in the initial update. Customers who have successfully updated their systems do not need to reinstall this update.Summary: This security update resolves several privately reported vulnerabilities in ActiveX Controls for Microsoft Office that were compiled with a vulnerable version of Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Other versions
- MS09-060 - Version: 1.1
- MS09-060 - Version: 1.2
- MS09-060 - Version: 1.0
- MS09-060 - Version: 1.3
- MS09-060 - Version: 1.4
- MS09-060 - Version: 1.5