CVE-2009-0901
Published Jul 29, 2009
Last updated 6 years ago
Overview
- Description
- The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka "ATL Uninitialized Object Vulnerability."
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-94
Evaluator
- Comment
- -
- Impact
- Please refer to this link http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx for mitigating factors and additional information.
- Solution
- Please refer to this link http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx for mitigating factors and additional information.
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:visual_c\\+\\+:2005:sp1_redistribution_pkg:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FA86F8B2-0211-4FF6-BE07-2E2EC06DFC37" }, { "criteria": "cpe:2.3:a:microsoft:visual_c\\+\\+:2008:redistribution_pkg:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9BA98FBB-255F-4AC9-B035-54C60EEE022B" }, { "criteria": "cpe:2.3:a:microsoft:visual_c\\+\\+:2008:sp1_redistribution_pkg:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B20EDFCC-8C10-4EBF-BCC6-1A17362E6676" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2005:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9271AF1C-9B1C-4ADB-9F54-E63EBA2910F9" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2005:sp1:64_bit_hosted_visual_c\\+\\+_tools:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E35016A-D55F-4607-8716-77AACB7B166C" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2008:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED077FFC-EBCC-4CD9-BF0E-0286B99C1965" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio:2008:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AB2C8C4-7E86-4736-9CE4-2E65E4EDBF02" }, { "criteria": "cpe:2.3:a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "85959AEB-2FE5-4A25-B298-F8223CE260D6" } ], "operator": "OR" } ] } ]