Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Vulnerabilities in Microsoft ATL Could Allow Remote Code Execution (973908)

Information

Severity

Severity

Critical

Family

Family

Windows : Microsoft Bulletins

CVSSv2 Base

CVSSv2 Base

10.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

14 years ago

Modified

Modified

4 years ago

Summary

This host is missing a critical security update according to Microsoft Bulletin MS09-037.

Insight

Insight

The multiple flaws are due to: - Bug in the ATL header that could allow reading a variant from a stream and leaving the variant type read with an invalid variant. When deleting the variant, it is possible to free unintended areas in memory that could be controlled by an attacker. - Error in 'CComVariant::ReadFromStream()' function used in the ATL header. This function does not properly restrict untrusted data read from a stream. - An bug in the ATL headers that could allow an attacker to force VariantClear to be called on a VARIANT that has not been correctly initialized. - Bugs in the ATL headers that handle instantiation of an object from data streams.

Affected Software

Affected Software

Windows Media Player 9/10/11 Microsoft Outlook Express 6 Service Pack 1 Microsoft Outlook Express 5.5 Service Pack 2 Microsoft Windows 2K Service Pack 4 and prior Microsoft Windows XP Service Pack 3 and prior Microsoft Windows 2003 Service Pack 2 and prior Microsoft Windows Vista Service Pack 1/2 and prior Microsoft Windows Server 2008 Service Pack 1/2 and prior

Solution

Solution

The vendor has released updates. Please see the references for more information.

Common Vulnerabilities and Exposures (CVE)