VDB
GSD-2009-2493
GSD-2009-2493
PUBLISHED
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Timeline
- Sep 5, 2006 CVE Published
- Sep 23, 2014 PoC Published
- Apr 15, 2026 Security Advisory
References
- http://www.adobe.com/support/security/bulletins/apsb09-11.html url
- 266108 vendor-advisory
- oval:org.mitre.oval:def:6304 vdb
- ADV-2009-2034 vdb
- TA09-223A third-party-advisory
- oval:org.mitre.oval:def:6621 vdb
- http://www.openoffice.org/security/cves/CVE-2009-2493.html url
- http://www.adobe.com/support/security/bulletins/apsb09-13.html url
- http://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1 url
- TA09-286A third-party-advisory
- http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx url
- ADV-2010-0366 vdb
- SSRT100013 vendor-advisory
- 36187 third-party-advisory
- TA09-342A third-party-advisory
- ADV-2009-2232 vdb
- http://www.adobe.com/support/security/bulletins/apsb09-10.html url
- 36374 third-party-advisory
- 38568 third-party-advisory
- http://www.adobe.com/support/security/advisories/apsa09-04.html url
…and 16 more