A few comments to yesterday's Out of Band

It is pretty typical – these things often happen, when I have a really bad Internet connection ;-) . However, I am back home and the connection is kind of better now…

I guess you have seen and heard about the two out of band updates we shipped yesterday. They are kind of special and I would like to make sure you are doing everything necessary to protect you and your customers. Therefore – even before you read the bulletins – read the Advisory which goes with the updates from yesterday called Vulnerabilities in Microsoft Active Template Library (ATL) Could Allow Remote Code Execution. Once you understand the problem space, get familiar with the two bulletins:

Now, the real problem is with the applications and controls developed by you. If you are a developer, make definitely sure, you read the corresponding article on MSDN: Active Template Library Security Update for Developers. In there you have a very good flowchart helping you to understand whether your component might be vulnerable. 

Last but definitely not least, ICASI was collaborating with Verizon Business to provide a free of charge scanning service to help you figuring out, whether your component is vulnerable. you find the information here:

  • The ICASI Alert
  • The Verizon Business Scanner

I hope this helps

Roger

Related posts:

  1. Out of Band Security Update to be Released
  2. MS08-067 Out of Band Released
  3. IMPORTANT: IE Vulnerability: Out of Band Release Scheduled for Tomorrow
  4. Security – One of The Key Reasons to Migrate to Windows Vista (part 1)
  5. MS09-017: An out-of-the-ordinary PowerPoint security update

Leave a Reply

  

  

  

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Calendar

July 2009
M T W T F S S
« Jun   Aug »
 12345
6789101112
13141516171819
20212223242526
2728293031