Q: After applying MS09-035 will end users see any changes to their user interface that would be unusual or different to normal when working with ActiveX controls in Internet Explorer? For example, unusual dialog boxes?
A: We are aware of active attacks on the msvidctl ActiveX component (see MS09-032). We are aware of a demonstration video available. However, we have seen no full PoC regarding the issues we released today.
A: Disabling ActiveX controls will mitigate the issues discussed in MS09-035. See Security Advisory 973882 for a full list of mitigations and workarounds. If ActiveX controls are disabled, then there is no risk to our customers.
A: No, installing the redistributable updates will only make the update available to runtime use and not design time. This means that the developer will still be using an unpatched version of ATL even though the runtime experience is patched
A: MS09-032 is specific to msvidctl, the OOB update takes care of the other issues in ATL vulnerabilities. Furthermore, the msvidctl was using a private version of the ATL which was not publicly available.
Q: This is specific to the Visual Studio patch. After the patch is installed (IDE update or C++ runtime updates), is the old version, which still has the vulnerability, be installed on the workstation? Or will it be replaced?
A: We recommend that you apply both the runtime and design-time patches for a developer machine running Visual studio. If you install both then the old bits will be replaced, if you install one or the other of the run/design-time updates then the other patch will not be applied and affected components will still be the old versions
Q: If a developer has a control that is vulnerable and does not recompile the control and someone who is using Internet Explorer has MS09-034 installed, will they be blocked from using the control in general or only from malicious code injection etc?
A: While the MS09-032 addresses known exploits, other components and controls are still vulnerable. MS09-034 provides mitigation in Internet Explorer to protect from potential attacks, and MS09-035 allows developers to correct their components and controls
A: MS09-034 is a Cumulative update and contains the fixes contained in MS09-019. Microsoft encourages customers to apply the latest cumulative critical update as soon as possible to protect customers.
A: As long as the MS09-034 update is installed then there are not specific problems in updating to Internet Explorer 8. That said, it is worth highlighting the fact that Internet Explorer 8 provides further security improvements (as it is the latest version)
Q: Can Microsoft provide info about current and future ActiveX controls that are being killbitted so Webmasters can scan their sites to see if they are in use? This will be a critical issue if Microsoft issues a killbit for an orphaned control without an owner.
Q: If a machine does not have the affected (or any) version of Visual Studio, does the MS09-034 patch still apply? If I understood correctly, they both address two different attack vectors for the same underlying issue within the ATL library.
A: The catalogs for WSUS have already been published (they are always released at the same time as the bulletins). If you are experiencing any delays you may wish to investigate possible proxy caching latency between you and microsoft.com.
A: The scenario you describe should not happen because the updated version of the Microsoft Visual C++ 2008 Redistributable (KB973551) contains the fixed version of the binaries so a scan should not flag the security update as required. Please call Customer Support Services at 1-800-MICROSOFT from free support for security updates.
A: MS09-034 includes other security fixes (unrelated to ATL), so we encourage everyone to apply the update. If Internet Explorer is not used on your environment you should assess the risk based on the binaries being updated.
Q: Since very little web browsing is performed on data center servers, is it critical to get these patches applied to our servers, or can this wait a few weeks until our standard maintenance window?
A: MS09-034 includes other security fixes not related to the Internet Explorer mitigations that will block ATL. Based on this you should evaluate how the impacted binaries are used in your specific scenario to assess the risk. That said, we highly encourage all our customers to apply the update to avoid being vulnerable.
Q: Killbits are trustworthy again after the MS09-034 update, right? So, MS09-034 also includes killbits for all vulnerable ActiveX controls whitelisted by default in Internet Explorer 7 and 8?
A: ActiveX security policy, such as killbits, work as expected after the Internet Explorer mitigation release with MS09-034 is applied on the system. Also, MS09-034 does not include killbits, but instead defense-in-depth fixes were introduced to block all known ATL vulnerabilities. As our investigation continues, further killbits might be released.
Q: So, assuming that I have probably currently installed several vulnerable ActiveX controls, how can an attacker exploit this? Does he just have to call them? And if so, is the user prompted about this again?
A: At this time we are not aware of an exploit that can take advantage of arbitrary controls. For example, regarding msvidctl which was fixed as part of MS09-032 update two weeks ago (in the July release) further code was needed to trigger the vulnerability. At this time we are not aware of any generic way of exploiting ActiveX controls. In order to understand whether your controls are vulnerable please submit them to
Q: How do I push that big red button of the second Internet Explorer mitigation mentioned that is not enabled by default? I mean, I have to assume that my customers are pushing that button and have to evaluate if my controls still work, right?
A: Correct. We highly encourage testing all controls and LOB to ensure that this mitigation does not break any applications. Further information can be found on Internet Explorer bulletin MS09-034 and on the SRD blog
Q: Windows 7 has reached the Release To Manufacturer (RTM) stage, but not yet available to the public. Will the Internet Explorer patch be in the RTM bits, and will there be any patches for the Release to Customers (RC) version?
A: Windows 7 RTM is not vulnerable to the vulnerabilities in the Internet Explorer Security Update. There are no known controls exposed to these issues included in Windows 7 RTM. However, the Internet Explorer Security Update contains a number of defenses in depth changes; the most critical of these defense in depth changes are included in Windows 7 RTM. Windows 7 also benefits from improved security and privacy protections such as /NX and DEP which are enabled in Internet Explorer 8 by default. Customers running versions other than Windows 7 RTM are unsupported.
Q: If ActiveX libraries are enabled in Firefox, will this update fix issues within Firefox? Is it vulnerable?
A: The Internet Explorer bulletin does not address any potential issues in Firefox or any other browsers.
Q: Does this mean that any ActiveX control built by any third party might contain remote code execution vulnerability due to the ATL vulnerability?
A: Yes, Microsoft has been working with third parties to identify vulnerable controls
Q: Using Internet Explorer 6 we do not allow active content to run in files on My Computer (Internet Explorer settings). Does this vulnerability bypass this mitigating control for MS09-0034 or MS09-035?
A: With this mitigation in place, attacks in the Local Machine Zone would be blocked. For example, if a local HTML file was attempting to exploit these vulnerabilities. But the primary attack vector, via the Internet zone, would not be blocked; you could still browse to malicious web sites and an exploit could succeed.
Q: Do we need to install the MS09-035 runtime patches to end user (non-developer) machines?A: The runtime patches for MS09-035 are updated versions of the Visual C++ Redistributable. Being a redistributable package, by definition this is redistributed with numerous non-Microsoft applications. Therefore any PCs that have an affected version of the Visual C++ Redistributable should install the runtime updates for the corresponding Visual C++ Redistributable version. PCs that have Visual Studio installed should install both the runtime and the design time updates.
Q: Regarding MS09-034: What guidance do you have for enterprise customers to determine if the optional defense in depth option (FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE) should be enabled?
A: Enterprise customers should evaluate if LOB applications might be impacted. For further information look at
Q: Do we need to install the MS09-035 runtime patches to end user (non-developer) machines?A: MS09-035 is a security update for developers. Customers who are not developers, and do not use Visual Studio or the public versions of the Microsoft Active Template Library (ATL), do not need to install MS09-035 but are strongly encouraged to download and install MS09-034 to benefit from improved defense in depth protections now available Internet Explorer.
Im going crazy, i just wasted those money, and there is nothing i can do. I have disabled all antivirus, i have updated windows fully, i have unistalled and reinstalled microsoft visual C++. I have tried every fix i could find on this forum. I just want to cry right now, im so tired of this *, im mostly sad i wasted my last money on this *.
c80f0f1006