Skip to main content

Microsoft Windows ATL COM Initialization Vulnerability( 14 October 2009 )

Last Update Date: 28 Jan 2011 Release Date: 14 Oct 2009 4410 Views

RISK: Medium Risk

A remote code execution vulnerability exists in the Microsoft ActiveX controls listed in the FAQ section of this vulnerability, which were compiled using the vulnerable Microsoft Active Template Library described in Microsoft Security Bulletin MS09-035. An attacker could exploit the vulnerability in these controls by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged on user.