Article ID: 956844 - Last Review: December 2, 2009 - Revision: 3.1 MS09-046: Vulnerability in the DHTML Editing Component ActiveX control could allow remote code execution
On This PageINTRODUCTION
Microsoft has released security bulletin MS09-046. To view the complete security bulletin, visit one of the following Microsoft Web sites:
How to obtain help and support for this security updateFor home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support Web site:http://support.microsoft.com/common/international.aspx?rdpath=4
(http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge e-mail support or to unlimited individual chat support by visiting the following Microsoft Web site: http://support.microsoft.com/oas/default.aspx?&prid=7552
(http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.MORE INFORMATIONMore information about this security updateKnown issues with this security updateThis security update adds a new version of the DHTML Editing Control that injects the following META elements into the document containing the DHTML Editing Control for each operation that targets the document's HTML.As part of the attack surface reduction effort, code that provided partial preservation of markup formatting was removed from the DHTML control. The new DHTML control sends data directly to MSHTML and returns HTML output. MSHTML and the DHTML control do not fully preserve formatting. MSHTML provides visual rendering of "normalized" HTML by adding missing elements. These normalization changes include adding the closing </td> tag, adding the <html> and <head> tags, and positioning the <style> tag and the <script> tag elements inside the <head> element. The DHTML control parses the HTML into a document model and then re-creates it from the model when you save the file. Additional formatting can be achieved by using the HTML Tidy tool on the output from the DHTML control. For more information about the HTML Tidy tool, visit the following Web site: http://www.w3.org/People/Raggett/tidy
(http://www.w3.org/People/Raggett/tidy)
Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
FILE INFORMATIONThe English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.
Windows 2000 file informationFor all supported editions of Microsoft Windows 2000 Service Pack 4Collapse this table
Windows XP and Windows Server 2003 file information
For all supported x86-based versions of Windows XPCollapse this table
For all supported x64-based versions of Windows Server 2003 and of Windows XP Professional x64 editionCollapse this table
For all supported x86-based versions of Windows Server 2003Collapse this table
For all supported IA-64-based versions of Windows Server 2003Collapse this table
APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|





















Back to the top