MS ATL ActiveX Controls for MS Office Could Allow Remote Code Execution (973965)

Summary
This host is missing a critical security update according to Microsoft Bulletin MS09-060.
Impact
Successful exploitation could allow remote attackers to execute arbitrary code with SYSTEM privileges, and can cause Denial of Service. Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms09-060
Insight
Multiple flaws are due to - Error in the Microsoft Active Template Library (ATL) within the ATL headers that handle instantiation of an object from data streams. - Error in the ATL headers, which could allow a string to be read with no ending NULL bytes, which could allow an attacker to manipulate a string to read extra data beyond the end of the string and thus disclose information in memory. - Error in the Microsoft Active Template Library (ATL) headers, which could allow attackers to call 'VariantClear()' on a variant that has not been correctly initialized, leading to arbitrary code execution.
Affected
Microsoft Office Outlook 2002/2003/2007 Microsoft Office Visio Viewer 2007
References