Home > Security News > Microsoft issues emergency Active Template Library updates
Security News:
EMAIL THIS

Microsoft issues emergency Active Template Library updates

By Robert Westervelt, News Editor
28 Jul 2009 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Microsoft released two emergency, out-of-band updates Tuesday, addressing flaws in the Active Template Library that affect Internet Explorer and Visual Studio.
SearchSecurity.com:
To get security news and tips delivered to your inbox, click here to sign up for our free newsletter.

The update to Internet Explorer also addresses issues being identified in a presentation at the 2009 Black Hat USA conference Wednesday. Researchers plan to demonstrate how to bypass killbits that were set to protect a machine against unsafe ActiveX controls, according to a report Monday by IDG's Robert McMillan. Researchers Mark Dowd, Ryan Smith and David Dewey will show a way of bypassing ActiveX control killbits in their presentation, "The Language of Trust: Exploiting Trust Relationships in Active Content."

The Internet Explorer update blocks vulnerabilities in controls that have been developed using versions of the ATL. MS09-034 is rated critical and affects all versions of IE. The update also repairs three memory corruption vulnerabilities that leave IE vulnerable to any malicious ActiveX in the wild. The flaws could be exploited by an attacker to take complete control of an affected system, Microsoft said.

"Customers who are currently up to date on their security updates are protected from known attacks related to this out-of-band release," Mike Reavey, director of the Microsoft Security Response Center said in a statement.

The holes in Visual Studio could be potentially serious since the tool is used by developers and independent software vendors to build components used in Windows. MS09-035 addresses three flaws in the Active Template Library of Visual Studio that would enable developers to build vulnerable applications.

"To ensure customers are protected as quickly as possible, Microsoft is working to identify all vulnerable Microsoft-authored controls and components and will provide additional updates," Reavey said.
SearchSecurity radio:

The ATL contains an uninitialized object vulnerability, a COM initialization vulnerability and a Null String vulnerability. The flaws can be exploited in drive-by attacks. An attacker can exploit the flaws in applications built using Visual Studio by setting up a malicious Web page.

"Patching urgently against this is recommended," said John Harrison, group product manager of Symantec Security Response. "One of aspects is you just don't know how pervasive a library may be and we've found previously that issues can show up in a variety of different software packages."

Technically some of the programs built inside of Visual Studio could be potentially vulnerable as well, said Jason Miller, the security data team manager at patch management vendor Shavlik Technologies LLC. Patching could be an issue for firms that have been building applications using Visual Studio, Miller said.

"It could be considered critical for companies out there using Visual Studio," Miller said. "If you are talking about a roll-out, this could take some time. They would have to repackage some of their DLLs if they determine they would be vulnerable by having their DLLs built by this product."

Tags: Windows Security: Alerts, Updates and Best PracticesSoftware Development MethodologyVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Windows Security: Alerts, Updates and Best Practices
Exploit code targets Internet Explorer zero-day display flaw
Windows 7 DoS flaw allows hackers to freeze Microsoft's newest OS
Microsoft patches serious Windows kernel flaws
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability
Microsoft issues SMB vulnerability advisory, patch pending

Software Development Methodology
Quiz: How to build secure applications
How to detect software tampering
Developers Need Help with Security Errors
Does an EULA make it truly illegal to decompile software?
SQL injection continues to trouble firms, lead to breaches
IBM acquires Ounce Labs for source code analysis
Software security threats and employee awareness training
Adobe patches ColdFusion vulnerability blocking website attack
nCircle statistics show rising Web application vulnerabilities
Common PCI questions: Web application firewalls or source code review?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BotHunter  (SearchSecurity.com)
principle of least privilege (POLP)  (SearchSecurity.com)
security identifier  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts