Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

MS09-035: Vulnerabilities in Visual Studio Active Template Libraries could allow remote code execution


INTRODUCTION

Microsoft has released security bulletin MS09-035. To view the complete security bulletin, visit one of the following Microsoft Web sites:

How to obtain help and support for this security update


Help installing updates:
Support for Microsoft Update

Security solutions for IT professionals:
TechNet Security Troubleshooting and Support

Help protect your computer that is running Windows from viruses and malware:
Virus Solution and Security Center

Local support according to your country:
International Support

↑ Back to the top


More Information

Prerequisites


If you are running Windows Server 2003 Service Pack 2 (SP2), you must install update 973825 before you install this security update.

For more information about update 973825, click the following article number to view the article in the Microsoft Knowledge Base:

973825 Error message when you try to install a large Windows Installer package or a large Windows Installer patch package in Windows Server 2003 Service Pack 2: "Error 1718 File was rejected by digital signature policy"

Additional information and known issues about this security update

For more information about this security update, click the following article number to view the article in the Microsoft Knowledge Base:
971089 Description of the update for Microsoft Visual Studio .NET 2003 Service Pack 1: July 28, 2009
971090 Description of the update for Microsoft Visual Studio 2005 Service Pack 1: July 28, 2009
971091 Description of the update for Microsoft Visual Studio 2008: July 28, 2009
971092 Description of the update for Microsoft Visual Studio 2008 Service Pack 1: July 28, 2009
973544 Description of the security update for Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package: July 28, 2009

973552 Description of the security update for Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package: July 28, 2009

973551
Description of the update for Microsoft Visual C++ 2008 Redistributable Package: July 28, 2009
973830
Description of the update for Microsoft Visual Studio 2005 Service Pack 1 64-bit Hosted Visual C++ Tools: July 28, 2009
973923 Description of the security update for the Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package (for previously installed versions): July 28, 2009

973924 Description of the security update for the Microsoft Visual C++ 2008 Redistributable Package (for previously installed versions): July 28, 2009

973673 MS09-035: Description of the ATL for Smart Devices security update for Visual Studio 2005 Service Pack 1: August 11, 2009

973674 MS09-035: Description of the ATL for Smart Devices security update for Visual Studio 2008: August 11, 2009

973675 MS09-035: Description of the ATL for Smart Devices security update for Visual Studio 2008 Service Pack 1: August 11, 2009

974616
An update rollup is available for Windows Embedded CE 6.0 (December 2009)
For more information about any known issues with specific releases of this software, click the following article number to view the article in the Microsoft Knowledge Base:

974054 Symbol files (PDBs) are not updated after you install update 971090 or 973830 for Visual Studio 2005 Service Pack 1 or update 971089 for Visual Studio .NET 2003 Service Pack 1

974055
Some DLL files are not updated when you install update 971091 for Visual Studio 2008
973825 Error message when you try to install a large Windows Installer package or a large Windows Installer patch package in Windows Server 2003 Service Pack 2: "Error 1718 File was rejected by digital signature policy"

974479 You receive a compile error in your ATL project after you install the Windows SDK 6.1 with Visual Studio 2008 Service Pack 1

↑ Back to the top


Additional affected products

In addition to the product versions that are specified in the "Applies to" section, this security update is meant to be used with the following products:

  • Microsoft Visual C++ 2008 Service Pack 1 Redistributable Package
  • Microsoft Visual C++ 2008 Redistributable Package
  • Microsoft Visual Studio 2005 Service Pack 1 64-bit Hosted Visual C++ Tools
  • Microsoft Visual C++ 2005 Service Pack 1 Redistributable Package

↑ Back to the top


Keywords: atdownload, kbbug, kbexpertiseinter, kbfix, kblangall, kbmustloc, kbsecbulletin, kbsecreview, kbsecurity, kbsecvulnerability, kbsurveynew, kb

↑ Back to the top

Article Info
Article ID : 969706
Revision : 4
Created on : 4/17/2018
Published on : 4/17/2018
Exists online : False
Views : 79