Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Microsoft > Patches and Vulnerabilities

July 29th, 2009, 16:17 GMT · By

Patch Critical Visual Studio Vulnerabilities

SHARE:

Adjust text size:


Security
Enlarge picture
The security bulletin released for Visual Studio Active Template Library is an integral part of a package of patches made available out-of-band, namely outside of the normal monthly update cycle, by Microsoft. The Microsoft Security Bulletin MS09-035 was released in conjunction with MS09-034 for Internet Explorer, and both come on top of MS09-032 a cumulative security update of ActiveX killbits released earlier this month.

With MS09-032, the software giant patched a vulnerability affecting the Microsoft Video ActiveX Control. However, independent security researchers demonstrated that the ActiveX killbits for the MSVidCtl.dll were insufficient to protect end users. Mark Dowd, Ryan Smith, David Dewey came up with an attack designed to bypass the blacklist set in place by the Redmond-based company, and essentially exploit the patched vulnerability.

“The two security updates together address separate CVEs but are being addressed out-of-band because they are related,” revealed Jonathan Ness, MSRC Engineering. “Allow me to explain: The relevant CVEs warranting the out-of-band release are included in the Visual Studio bulletin (MS09-035) CVE-2009-0901 and CVE-2009-2493 (ATL header and libraries update), and are also discussed in Security Advisory 973882. These are the vulnerabilities in the ATL that could be exposed in various controls and are currently being discussed publicly. However, we’ve also released an Internet Explorer update. This is being released to help protect customers while developers update their controls as defense-in-depth measures in Internet Explorer that help prevent exploitation of all known ATL vulnerabilities.”

Microsoft acknowledged that the combination of vulnerable components loaded by Internet Explorer, together with the security flaws in the Active Template Library, created a vector of attack that could have been exploited by attackers. However, Microsoft underlined that there were no attacks designed to exploit the vulnerabilities patched via its out-of-band security update. The software giant noted that it was aware of just a single active attack on an ATL vulnerability targeting the msvidctl.dll control, patched originally by the killbits offered through MS09-032.

“Microsoft also published Security Advisory 973882 to provide comprehensive guidance to customers regarding the issue. The advisory provides information on what steps developers can take to verify if controls and components developed using Active Template Library are vulnerable, and if so, the steps to take to rebuild and resolve the vulnerability. The advisory also includes information on specific steps customers can take to protect themselves from attacks involving vulnerable controls and components that were developed using affected versions of the Active Template Library,” stated Mike Reavey, director of the Microsoft Security Response Center.

At the same time, the software giant confirmed that the two out-of-band vulnerabilities would render useless any attempts to bypass the killbit measures set in place with MS09-032. On unpatched systems, an attacker could force MSVidCtl.dll to load in IE, and execute arbitrary code on a victim's computer, effectively taking over the machine.

“Customers who are currently up to date on their security updates are protected from known attacks related to this out-of-band release. Microsoft strongly encourages all Visual Studio and Internet Explorer customers to test and deploy these updates as soon as possible. To ensure customers are protected as quickly as possible, Microsoft is working to identify all vulnerable Microsoft-authored controls and components and will provide additional updates. The company is also working to provide guidance and information that ISVs can use to determine if their components and controls are affected and what they can do to address them,” Reavey promised.

TELL US WHAT YOU THINK:

1,740 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Download Windows 7 IDX and RC IE8 Patch

IE Proof-of-Concept Attack Exploits Kilbitted ActiveX Control

Microsoft Office Visualization Tool Available for Download

Download Forefront Threat Management Gateway Tools and SDK Beta 3

Windows 7 RTM Build 7600.16385 DVD ISO SHA-1 and MD5 Information

READER COMMENTS:


Comment #1 by: Phillip Munn on 29 Jul 2009, 18:52 UTC reply to this comment

Just wanted you and your readers to be aware that users that have not installed C++ with Visual Studio are having terrible issues with this update.
Windows update keeps offering it and it keeps on failing to install.

Check out threads here ...
https://connect.microsoft.com/VisualStudio/feedback/ViewFeedback.aspx?FeedbackID=478117

and here ...
http://social.msdn.microsoft.com/Forums/en-US/vbgeneral/thread/3b465fe1-d82f-4c80-90ab-eeab2e11d20c

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM