Home Microsoft CVE-2009-2493
Back to Microsoft

CVE-2009-2493

Microsoft Visual Studio - Active Template Library (ATL)

Microsoft CVSS 8.8 Updated May 29, 2026

Executive Risk Summary

"The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control. This vulnerability can be exploited by an attacker to execute arbitrary code on the affected system."

Anticipated Attack Path

  1. 1. An attacker crafts a malicious HTML document with an ATL component or control
  2. 2. The attacker sends the malicious HTML document to the victim
  3. 3. The victim opens the malicious HTML document, which executes the arbitrary code

Am I Vulnerable?

  • Check if the system is running a vulnerable version of Microsoft Visual Studio or Windows
  • Verify if the ATL component or control is used in any applications
  • Apply the patch MS09-037 to fix the vulnerability

Operational Audit Arsenal

Target Type DLL
Target Asset atl.dll
Standard Path C:\Windows\System32
PowerShell
# 🛠️ Senior Engineer Universal Audit
# Target: atl.dll (DLL)
$Targets = 'atl.dll'
$SearchPaths = @("$env:windir\System32", "$env:ProgramFiles", "${env:ProgramFiles(x86)}")

Get-ChildItem -Path $SearchPaths -Include $Targets -Recurse -ErrorAction SilentlyContinue | 
Select-Object FullName, @{Name="Version";Expression={$_.VersionInfo.ProductVersion}}

Patch Impact Forecast

Reboot Required Likely

Moderate

Internal Work Notes

ATL COM Initialization Vulnerability (CVE-2009-2493) - Apply patch MS09-037 to fix the vulnerability

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Official Advisoryhttp://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx
Official Advisoryhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html
Official Advisoryhttp://marc.info/?l=bugtraq&m=126592505426855&w=2
Official Advisoryhttp://secunia.com/advisories/35967
Official Advisoryhttp://secunia.com/advisories/36187
Official Advisoryhttp://secunia.com/advisories/36374
Official Advisoryhttp://secunia.com/advisories/36746
Official Advisoryhttp://secunia.com/advisories/38568
Official Advisoryhttp://secunia.com/advisories/41818
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-264648-1
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1020775.1-1
Adobe Bulletinhttp://www.adobe.com/support/security/advisories/apsa09-04.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-10.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-11.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-13.html
Official Advisoryhttp://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1
Official Advisoryhttp://www.openoffice.org/security/cves/CVE-2009-2493.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-195A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-223A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-286A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-342A.html
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2034
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2232
Official Advisoryhttp://www.vupen.com/english/advisories/2010/0366
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-035
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-055
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-060
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-072
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6245
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6304
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6421
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6473
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6621
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6716
Official Advisoryhttp://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx
Official Advisoryhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html
Official Advisoryhttp://marc.info/?l=bugtraq&m=126592505426855&w=2
Official Advisoryhttp://secunia.com/advisories/35967
Official Advisoryhttp://secunia.com/advisories/36187
Official Advisoryhttp://secunia.com/advisories/36374
Official Advisoryhttp://secunia.com/advisories/36746
Official Advisoryhttp://secunia.com/advisories/38568
Official Advisoryhttp://secunia.com/advisories/41818
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-264648-1
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1
Official Advisoryhttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1020775.1-1
Adobe Bulletinhttp://www.adobe.com/support/security/advisories/apsa09-04.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-10.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-11.html
Adobe Bulletinhttp://www.adobe.com/support/security/bulletins/apsb09-13.html
Official Advisoryhttp://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1
Official Advisoryhttp://www.openoffice.org/security/cves/CVE-2009-2493.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-195A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-223A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-286A.html
Official Advisoryhttp://www.us-cert.gov/cas/techalerts/TA09-342A.html
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2034
Official Advisoryhttp://www.vupen.com/english/advisories/2009/2232
Official Advisoryhttp://www.vupen.com/english/advisories/2010/0366
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-035
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-037
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-055
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-060
MSRC Advisoryhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-072
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6245
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6304
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6421
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6473
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6621
Official Advisoryhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6716

Related Microsoft Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.