CVE Database
/

CVE-2009-2493

Back to search

CVE-2009-2493

Published: Jul 29, 2009

Modified: May 27, 2026

PUBLISHED

Description

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

266108
vendor-advisory
x_refsource_SUNALERT
oval:org.mitre.oval:def:6304
vdb-entry
signature
x_refsource_OVAL
ADV-2009-2034
vdb-entry
x_refsource_VUPEN
TA09-223A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:6621
vdb-entry
signature
x_refsource_OVAL
TA09-286A
third-party-advisory
x_refsource_CERT
MS09-035
vendor-advisory
x_refsource_MS
ADV-2010-0366
vdb-entry
x_refsource_VUPEN
SSRT100013
vendor-advisory
x_refsource_HP
MS09-072
vendor-advisory
x_refsource_MS
HPSBMA02488
vendor-advisory
x_refsource_HP
36187
third-party-advisory
x_refsource_SECUNIA
TA09-342A
third-party-advisory
x_refsource_CERT
ADV-2009-2232
vdb-entry
x_refsource_VUPEN
36374
third-party-advisory
x_refsource_SECUNIA
38568
third-party-advisory
x_refsource_SECUNIA
MS09-037
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:6245
vdb-entry
signature
x_refsource_OVAL
oval:org.mitre.oval:def:6716
vdb-entry
signature
x_refsource_OVAL
36746
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:6421
vdb-entry
signature
x_refsource_OVAL
41818
third-party-advisory
x_refsource_SECUNIA
35967
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2009:053
vendor-advisory
x_refsource_SUSE
1020775
vendor-advisory
x_refsource_SUNALERT
TA09-195A
third-party-advisory
x_refsource_CERT
MS09-060
vendor-advisory
x_refsource_MS
MS09-055
vendor-advisory
x_refsource_MS
264648
vendor-advisory
x_refsource_SUNALERT
oval:org.mitre.oval:def:6473
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now