Home Microsoft CVE-2009-0901
Back to Microsoft

CVE-2009-0901

Microsoft Visual Studio - Active Template Library (ATL)

Microsoft CVSS 8.8 Updated May 29, 2026

Executive Risk Summary

"The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control. This vulnerability can be exploited by an attacker to gain control of the affected system."

Anticipated Attack Path

  1. 1. Initial Exploitation
  2. 2. Privilege Escalation
  3. 3. Lateral Movement

Am I Vulnerable?

  • Verify ATL version
  • Check for malicious streams
  • Monitor system logs for suspicious activity

Operational Audit Arsenal

Target Type DLL
Target Asset atl.dll
Standard Path C:\Windows\System32
PowerShell
# 🛠️ Senior Engineer Universal Audit
# Target: atl.dll (DLL)
$Targets = 'atl.dll'
$SearchPaths = @("$env:windir\System32", "$env:ProgramFiles", "${env:ProgramFiles(x86)}")

Get-ChildItem -Path $SearchPaths -Include $Targets -Recurse -ErrorAction SilentlyContinue | 
Select-Object FullName, @{Name="Version";Expression={$_.VersionInfo.ProductVersion}}

Patch Impact Forecast

Reboot Required Likely

System restart required

Internal Work Notes

ATL Uninitialized Object Vulnerability - MS09-035

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Official Advisoryhttp://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx
Official Advisoryhttp://marc.info/?l=bugtraq&m=126592505426855&w=2
Official Advisoryhttp://secunia.com/advisories/35967
Official Advisoryhttp://secunia.com/advisories/36187
Official Advisoryhttp://secunia.com/advisories/36374
Official Advisoryhttp://secunia.com/advisories/36746
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1
Adobe Bulletinhttp://www.adobe.com/support/security/advisories/apsa09-04.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-10.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-11.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-13.html
Official Advisoryhttp://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1
Official Advisoryhttp://www.securityfocus.com/bid/35832
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-195A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-223A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-286A.html
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2034
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2232
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-035
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-060
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6289
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6311
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6373
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7581
Official Advisoryhttp://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx
Official Advisoryhttp://marc.info/?l=bugtraq&m=126592505426855&w=2
Official Advisoryhttp://secunia.com/advisories/35967
Official Advisoryhttp://secunia.com/advisories/36187
Official Advisoryhttp://secunia.com/advisories/36374
Official Advisoryhttp://secunia.com/advisories/36746
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1
Adobe Bulletinhttp://www.adobe.com/support/security/advisories/apsa09-04.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-10.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-11.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-13.html
Official Advisoryhttp://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1
Official Advisoryhttp://www.securityfocus.com/bid/35832
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-195A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-223A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-286A.html
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2034
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2232
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-035
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-060
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6289
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6311
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6373
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7581

Related Microsoft Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.