Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

MS ATL ActiveX Controls for MS Office Could Allow Remote Code Execution (973965)

Information

Severity

Severity

Critical

Family

Family

Windows : Microsoft Bulletins

CVSSv2 Base

CVSSv2 Base

9.3

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

14 years ago

Modified

Modified

4 years ago

Summary

This host is missing a critical security update according to Microsoft Bulletin MS09-060.

Insight

Insight

Multiple flaws are due to - Error in the Microsoft Active Template Library (ATL) within the ATL headers that handle instantiation of an object from data streams. - Error in the ATL headers, which could allow a string to be read with no ending NULL bytes, which could allow an attacker to manipulate a string to read extra data beyond the end of the string and thus disclose information in memory. - Error in the Microsoft Active Template Library (ATL) headers, which could allow attackers to call 'VariantClear()' on a variant that has not been correctly initialized, leading to arbitrary code execution.

Affected Software

Affected Software

Microsoft Office Outlook 2002/2003/2007 Microsoft Office Visio Viewer 2007

Solution

Solution

The vendor has released updates. Please see the references for more information.

Common Vulnerabilities and Exposures (CVE)