• Narrow screen resolution
  • Wide screen resolution
  • Auto width resolution
  • Increase font size
  • Decrease font size
  • Default font size
  • default color
  • red color
  • green color

Sunday
Sep 05th
Microsoft Updates for Multiple Vulnerabilities PDF Print E-mail

Microsoft Updates for Multiple Vulnerabilities

Original release date: August 11, 2009
Last revised: --
Source: US-CERT

Systems Affected

  • Microsoft Windows and Windows Server
  • Microsoft Office
  • Remote Desktop Connection Client for Mac 2.0

 


Overview

Microsoft has released updates to address vulnerabilities in Microsoft Windows, Windows Server, Office Web Components and Remote Desktop Connection for Mac.


I. Description

Microsoft has released multiple security bulletins for critical vulnerabilities in Windows, Windows Server, Office Web Components, and Remote Desktop Connection for Mac. These bulletins are described in the Microsoft Security Bulletin Summary for August 2009.

Microsoft Security Bulletin MS09-037 includes updates for Microsoft components to address vulnerabilities in the Active Template Library (ATL). Vulnerabilities present in the ATL can cause vulnerabilities in the resulting ActiveX controls and COM components. Any ActiveX control or COM component that was created with a vulnerable version of the ATL may be vulnerable, including ones distributed by third-party developers.

Developers should update the ATL as described in the previously released Microsoft Security Bulletin MS09-035 in order to stop creating vulnerable controls. To address vulnerabilities in existing controls, recompile the controls using the updated ATL. Further discussion about the ATL vulnerabilities can be found in the Microsoft Security Advisory 973882.


II. Impact

An attacker may be able to execute arbitrary code, in some cases without user interaction.


III. Solution

Apply updates from Microsoft

Microsoft has provided updates for these vulnerabilities in the Microsoft Security Bulletin Summary for August 2009. The security bulletin describes any known issues related to the updates. Administrators are encouraged to note these issues and test for any potentially adverse effects. Administrators should consider using an automated update distribution system such as Windows Server Update Services (WSUS).

 


IV. References

 

What our customers are saying

Jeff S (Wilton, CT)---Scott has been a tremendous resource in helping our company determine our IT needs. As a start-up, it was comforting to know that someone was not pushing product, but acting as a consultant to determine what the best solution is for our needs.

Tech Login




News Ticker

I am here

Home Tech News Windows News Microsoft Updates for Multiple Vulnerabilities