Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • WinDeals
  • E-Books
  • Lounge
  • Polls
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Patch Watch>ATL flaw makes IE vulnerable to attack

ATL flaw makes IE vulnerable to attack

Posted on December 10, 2009 by Susan Bradley in Patch Watch
Tweet

Susan Bradley 1 ATL flaw makes IE vulnerable to attack By Susan Bradley

Yet another Active Template Library hole makes Internet Explorer susceptible to remote code execution.

All versions of IE require a patch that Microsoft released this week to block a malicious ActiveX control from taking over your system.


MS09-072 (976325)
IE patch prevents Web-based infection

It’s only fitting that the last set of Microsoft patches for 2009 plugs holes in Internet Explorer’s ActiveX controls. MS09-072 (976325) is a high priority for all IE users. It prevents a payload that a hacker created using Microsoft’s Active Template Library (ATL) from launching a remote-code execution attack when you visit an infected site.

The patch also repairs some other issues: (1) an HTML object-corruption vulnerability, which was described last month in MS security advisory 977981, and (2) four separate glitches addressed in MS09-054 and KB article 976749, primarily affecting Web sites outside the U.S.

Regarding the main problem, the update combines fixes for several ATL problems that have been reported in the past several months. Most recently, additional updates have been found to be required. These updates plug holes in IE to protect against controls developed using ATL version prior to MS09-035 (969706) last July.

I expect to see exploits of these holes start to circulate in the near future. For this reason, you’re urged to apply these patches to your computers as soon as possible.

MS09-073 (975539)
WordPad and Word are the focus of new threats

You may be offered patches this month for three Microsoft word processors: Word, WordPad, and the Works suite. However, there are already reports of problems with MS09-073.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. Internet Explorer is target of zero-day attack
  2. Unpatched IE flaw leaves all users vulnerable
  3. Word 2000/XP flaw makes docs dangerous
  4. Heavy patch week to block Web-based attacks
  5. Protect yourself from the coming ASN.1 attack
= Paid content

All Windows Secrets articles posted on 2009-12-10:

  • Introduction Free subscribers: watch for an invite next week
  • Top Story Secure flash drives keep you safe on the road
  • Known Issues Credit-card extended warranties come in handy
  • Wacky Web Week Tetris may not be so random after all
  • LangaList Plus How to correct Msconfig ghost entries
  • In the Wild Windows 7 suffers from Server Message Block flaw
  • Patch Watch ATL flaw makes IE vulnerable to attack
  •  Show all articles on a single page
Susan Bradley

About Susan Bradley

Susan Bradley is a Small Business Server and Security MVP, a title awarded by Microsoft to independent experts who do not work for the company. She's also a partner in a California CPA firm.
View all posts by Susan Bradley →

WinDeals

WinDeals offers subscribers regular discounts — of up to 50 percent off — on software and technology products. Read moreยป

View current deals
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.56
  • LizaMoon infection: a blow-by-blow account 4.46
  • RPV: Win7′s least-known data-protection system 4.35
  • Recovery: the last step in total data security 4.31
  • The sorry tale of the (un)Secure Sockets Layer 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Get wired performance from your Wi-Fi network 4.24
  • Caution: Bumps in the road to IPv6 4.23
  • Patch Watch adds problem-patch update chart 4.23
  • ZeuS Trojan reinvents itself as bots rock on 4.22
  • Pros and cons of a ‘keyfile’ password 4.21
  • April brings showers of browser patches 4.20
  • Readers comment on the LizaMoon infection story 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • The advanced system-recover toolkit 4.18
  • One year and 99 security bulletins later 4.18
  • Don’t pay for software you don’t need — Part 3 4.17
  • What to do when Windows refuses to boot 4.17
  • Make the most of Windows 7′s Libraries 4.16
  • Keeping you up to date: say no to .NET — again 4.16
  • Internet Explorer gets another round of patches 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Big-time Wi-Fi security for the small office 4.14
  • Office File Validation patch leads to problems 4.14
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb