Encyclopedia

MS09-060

 
Threat LevelLow threatDamageHighDistributionNot widespread
Common name:MS09-060
Technical name:MS09-060
Threat level:Medium
Alias:Vulnerabilities in Microsoft Active Template Library (ATL) ActiveX Controls for Microsoft Office Could Allow Remote Code Execution
Type:Vulnerability
Effects:  

It is a group of critical vulnerabilities in Active Template Library (ATL) Controls for Office, which allows hackers to gain remote control of the affected computer with the same privileges as the logged on user and to disclose information.

Affected platforms:

Other

First detected on:Oct. 14, 2009
Detection updated on:Oct. 14, 2009
StatisticsNo

Brief Description 

    

MS09-060 is not categorized as virus, worm, Trojan or backdoor. It is a group of critical vulnerabilities in Active Template Library (ATL) Controls for Office, which allows arbitrary code to be remotely executed and information to be disclosed.

The affected components are:

  • Outlook 2007 on Office 2007.
  • Outlook 2003 on Office 2003.
  • Outlook 2002 on Office XP.
  • Visio Viewer 2007/2003/2002.

If exploited successfully, MS09-060 allows hackers to gain remote control of the affected computer with the same privileges as the logged on user. It also could allow an attacking user to access any data available to the logged on user.

MS09-060 is usually exploited by creating a specially crafted web page and enticing users to access it. The link to the website can be distributed using several methods, such as email, instant messaging programs, etc.

 

If you have any of the vulnerable Office components, it is recommended to download and apply the security patch for this vulnerability. Click here to access the web page for downloading the patch.

Last updated:  14/10/2009 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]