Antivirus and Security Software from Sophos

Soporte en línea

Mantenimiento de productos

Soporte técnico

Servicios de soporte

Centro de recursos

Vulnerability: MS09-037. Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution

Back to Latest vulnerabilities homepage (inglés)

Click any highlighted term for further explanation.

Details
Vulnerability name/brief description

Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution (973908)

CVE/CAN name

CVE-2008-0015, CVE-2008-0020, CVE-2009-0901, CVE-2009-2493, CVE-2009-2494

Vendor threat level Critical
SophosLabs threat level Critical
Solution

MS09-037

Vendor description This security update resolves several privately reported vulnerabilities in Microsoft Active Template Library (ATL). The vulnerabilities could allow remote code execution if a user loaded a specially crafted component or control hosted on a malicious website. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
SophosLabs comments This security update modifies the ATL headers so that components and controls built using the headers can safely initialize from a data stream. It also provides updated versions of Windows components and controls built using the corrected ATL headers. Although the vulnerabilities addressed in this update are all privately reported there are several, most of which are exploitable by visiting a malicious web page which is an attack vector easily leveraged via spam email and social engineering attacks. For this reason SophosLabs have assigned this update a threat rating of critical.
SophosLabs testing result N/A
Currently known exploits Exp/VidCtl-A - CVE-2008-0015
Mal/JSShell-D - CVE-2008-0015
First sample seen 6th July 2009
Discovery date 11th August 2009
Affected software Microsoft Windows 2000 Service Pack 4
Windows XP Service Pack 2 and Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Windows Vista, Windows Vista Service Pack 1, and Windows Vista Service Pack 2
Windows Vista x64 Edition, Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
References http://www.microsoft.com/technet/security/Bulletin/ms09-037.mspx
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0015
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0020
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0901
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2494
Credits Microsoft MAPP
Revisions 12 August 2009 - initial analysis written

Explanation of terms

Vulnerability Name/Brief Description:
Vendor identifier plus a brief description of the type of attack.

CVE/CAN Name:
Currently assigned CVE name. If a CVE name doesn't exist the CAN name will be used until a CVE has been assigned.

Vendor Threat Level:

Threat level assigned by the vendor

SophosLabs Threat Level:
Threat level assigned by SophosLabs

  • LOW RISK - There is little chance of this vulnerability being actively exploited by malware.
  • MEDIUM RISK - There is a possibility of this vulnerability being actively exploited by malware.
  • HIGH RISK - There is a strong possibility of this vulnerability being actively exploited by malware.
  • CRITICAL RISK - This vulnerability will almost certainly be actively exploited by malware.

Solution:
Vendor-supplied Patch identifier and recommended solution, or workaround if applicable.

Vendor Description:
Summary of the cause and potential effect of the vulnerability provided by the vendor.

SophosLabs Comments:
SophosLabs' opinions and observations of the vulnerability in question.

SophosLabs Testing Result:
Details of completed lab testing, if applicable. Please note that the lab test environment may differ significantly from user environments.

Currently Known Exploits:
List of identities for known exploits, if applicable.

First Sample Seen:
Date of the first sample seen by SophosLabs.

Discovery Date:
Date of the earliest known publically disclosed advisory.

Affected Software:
Vulnerable platforms and software versions.

Si necesita más ayuda, póngase en contacto con soporte técnico.