Home > Security News > Microsoft issues emergency Active Template Library updates
Security News:
EMAIL THIS

Microsoft issues emergency Active Template Library updates

By Robert Westervelt, News Editor
28 Jul 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft released two emergency, out-of-band updates Tuesday, addressing flaws in the Active Template Library that affect Internet Explorer and Visual Studio.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

The update to Internet Explorer also addresses issues being identified in a presentation at the 2009 Black Hat USA conference Wednesday. Researchers plan to demonstrate how to bypass killbits that were set to protect a machine against unsafe ActiveX controls, according to a report Monday by IDG's Robert McMillan. Researchers Mark Dowd, Ryan Smith and David Dewey will show a way of bypassing ActiveX control killbits in their presentation, "The Language of Trust: Exploiting Trust Relationships in Active Content."

The Internet Explorer update blocks vulnerabilities in controls that have been developed using versions of the ATL. MS09-034 is rated critical and affects all versions of IE. The update also repairs three memory corruption vulnerabilities that leave IE vulnerable to any malicious ActiveX in the wild. The flaws could be exploited by an attacker to take complete control of an affected system, Microsoft said.

"Customers who are currently up to date on their security updates are protected from known attacks related to this out-of-band release," Mike Reavey, director of the Microsoft Security Response Center said in a statement.

The holes in Visual Studio could be potentially serious since the tool is used by developers and independent software vendors to build components used in Windows. MS09-035 addresses three flaws in the Active Template Library of Visual Studio that would enable developers to build vulnerable applications.

"To ensure customers are protected as quickly as possible, Microsoft is working to identify all vulnerable Microsoft-authored controls and components and will provide additional updates," Reavey said.
SearchSecurity radio:

The ATL contains an uninitialized object vulnerability, a COM initialization vulnerability and a Null String vulnerability. The flaws can be exploited in drive-by attacks. An attacker can exploit the flaws in applications built using Visual Studio by setting up a malicious Web page.

"Patching urgently against this is recommended," said John Harrison, group product manager of Symantec Security Response. "One of aspects is you just don't know how pervasive a library may be and we've found previously that issues can show up in a variety of different software packages."

Technically some of the programs built inside of Visual Studio could be potentially vulnerable as well, said Jason Miller, the security data team manager at patch management vendor Shavlik Technologies LLC. Patching could be an issue for firms that have been building applications using Visual Studio, Miller said.

"It could be considered critical for companies out there using Visual Studio," Miller said. "If you are talking about a roll-out, this could take some time. They would have to repackage some of their DLLs if they determine they would be vulnerable by having their DLLs built by this product."

Tags: Windows Security: Alerts, Updates and Best PracticesSoftware Development MethodologyVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Windows Security: Alerts, Updates and Best Practices
Microsoft repairs Excel flaws, warns of new IE vulnerability
Microsoft to address eight security vulnerabilities in Windows, Office
Microsoft patching issue tied to Alureon rootkit
Windows blue screen may be result of rootkit infection
Microsoft blue screen affecting few corporate PCs
Microsoft patches SMB flaws, Hyper-V problem in big update
Microsoft to fix 26 flaws in Windows, Office
Microsoft warns that IE zero-day vulnerability causes data leakage
Microsoft issues critical security update, blocks IE 6 attacks
Microsoft emergency IE update to block latest corporate attacks

Software Development Methodology
Secure software development is difficult, but tools, techniques improving, expert says
Securing naming and directory services for application defense-in-depth
SANS Institute, MITRE release new top 25 dangerous coding errors list
Improving software with the Building Security in Maturity Model (BSIMM)
Microsoft extends SDL program, adds Agile development template
Malware in Google attacks uses spaghetti code
Self-defending Web applications thwart attacks
Information security book excerpts and reviews
Software piracy group offers cash to whistleblowers
Quiz: How to build secure applications

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BotHunter  (SearchSecurity.com)
principle of least privilege (POLP)  (SearchSecurity.com)
security identifier  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts