Article ID: 973965 - Last Review: May 23, 2012 - Revision: 4.0 MS09-060: Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office could allow remote code execution
On This PageINTRODUCTION
Microsoft has released security bulletin MS09-060. To view the complete security bulletin, visit one of the following Microsoft Web sites:
How to obtain help and support for this security updateHelp installing updates: Support for Microsoft Update (http://support.microsoft.com/ph/6527)Security solutions for IT professionals: TechNet Security Troubleshooting and Support (http://technet.microsoft.com/security/bb980617.aspx) Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center (http://support.microsoft.com/contactus/cu_sc_virsec_master) Local support according to your country: International Support (http://support.microsoft.com/common/international.aspx) MORE INFORMATIONKnown issues and additional information about this security updateFor more information about this security update and for information about any known issues with specific releases of this software, click the following article numbers to view the articles in the Microsoft Knowledge Base:972363
(http://support.microsoft.com/kb/972363/
)
MS09-060: Description of the security update for Outlook 2007: October 13, 2009
973702
(http://support.microsoft.com/kb/973702/
)
MS09-060: Description of the security update for Microsoft Outlook 2002: October 13, 2009
973705
(http://support.microsoft.com/kb/973705/
)
MS09-060: Description of the security update for Outlook 2003: October 13, 2009
973709
(http://support.microsoft.com/kb/973709/
)
MS09-060: Description of the security update for Visio Viewer 2007: October 13, 2009
974234
(http://support.microsoft.com/kb/974234/
)
MS09-060: Description of the security update for the 2007 Office system: October 13, 2009
974554
(http://support.microsoft.com/kb/974554/
)
MS09-060: Description of the security update for Office 2003: October 13, 2009
974556
(http://support.microsoft.com/kb/974556/
)
MS09-060: Description of the security update for Office XP: October 13, 2009
Where is the update for Visio Viewer 2002 and Visio Viewer 2003?We recommend that all users of Visio Viewer 2003 and Visio Viewer 2003 upgrade to the latest, free version of Visio Viewer 2007 to address this security vulnerability. Users who cannot upgrade should apply the update from MS09-034. This Internet Explorer update mitigates the attack vector for affected Visio Viewer platforms. Users may also apply the kill bit for the affected control by using the procedures that are listed in the workaround sections of this bulletin. A kill bit for these controls will be included in a future cumulative security update for Internet Explorer.For more information about the cumulative security update for Internet Explorer, MS09-034, click the following article number to view the article in the Microsoft Knowledge Base: 972260
(http://support.microsoft.com/kb/972260/
)
MS09-034: Cumulative security update for Internet Explorer
Why are Knowledge Base articles 974554, 974556, and 974234 not listed in the security bulletin?These packages do not contain security updates and do not correct any security-related issues. However, these updates resolve a problem that can cause programs that use Outlook View Control with Forms 2.0, such as Microsoft Office Outlook with Business Contact Manager, to stop functioning as expected after Security Update. If you use Outlook View Control with Forms 2.0, we encourage you to apply these updates after installing the security updateAPPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
