<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Inside the Active Template Library (ATL) Security Update</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update/RSS"></atom:link>
	<image>
		<url>http://ecn.channel9.msdn.com/o9/previewImages/100/481147_100x75.jpg</url>
		<title>Channel 9 - Inside the Active Template Library (ATL) Security Update</title>
		<link></link>
	</image>
	<description>
Today, Microsoft announced the details of an out-of-band&amp;nbsp;security update that impacts ATL components&amp;nbsp;and controls (like ActiveX controls, for example) -&amp;gt;&amp;nbsp;Developers
 who have built controls using vulnerable versions of ATL should take immediate action to review and identify any vulnerabilities, modify and recompile their affected controls and components using the updated versions of ATL and finally distribute a non-vulnerable
 version of the controls and components to their customers. 
Here, Damien Watkins&amp;nbsp;from the VC&amp;#43;&amp;#43; team and Damian Hasse and Jonathan Ness from MSRC Engineering review the steps to identify and address vulnerable controls and components. Of course, being a Channel 9 interview, we dig into various aspects of the problem
 without veering away from the goal here: helping you understand the exact issues with this vulnerability. If you own a component or control that uses ATL, then you will know what you need to do to prevent a possible attack.
 
&amp;nbsp;Please visit the URLs below as soon as possible for detailed information on this vulnerability. 
Resources discussed in this video are available on MSDN: 
Active Template Library Security Update and Developers Detailed technical information on this security release for ATL developers: 
http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx 
Additional information on this security release is available on the 
Security Research &amp;amp; Defense blogOverview with background &amp;#43; table of links:&amp;nbsp; 
http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx 
IE mitigation explanation:&amp;nbsp; 
http://blogs.technet.com/srd/archive/2009/07/28/internet-explorer-mitigations-for-atl-data-stream-vulnerabilities.aspx 
Deep dive for developers:&amp;nbsp; 
http://blogs.technet.com/srd/archive/2009/07/28/atl-vulnerability-developer-deep-dive.aspx 
How msvidctl.dll is related:&amp;nbsp; 
http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspxMichael Howard&#39;s perspective on this issue: 
http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx 
 
</description>
	<link></link>
	<language>en</language>
	<pubDate>Fri, 24 May 2013 22:38:28 GMT</pubDate>
	<lastBuildDate>Fri, 24 May 2013 22:38:28 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Inside the Active Template Library (ATL) Security Update</title>
		<description>
			<![CDATA[
<p>When is the MSDN page going to be active? <a href="http://go.microsoft.com/?linkid=9674481">
http://go.microsoft.com/?linkid=9674481</a>&nbsp;doesn't work yet.</p>
<p>posted by cqb</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update#c633844042070000000</link>
		<pubDate>Tue, 28 Jul 2009 18:56:47 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update#c633844042070000000</guid>
		<dc:creator>cqb</dc:creator>
	</item>
	<item>
		<title>Re: Inside the Active Template Library (ATL) Security Update</title>
		<description>
			<![CDATA[
<p>The link is now live.</p>
<p>C</p>
<p>&nbsp;</p>
<p>Decision tree from the article and this interview:</p>
<p>&nbsp;</p>
<p><a rel="lightbox" href="http://i.msdn.microsoft.com/ee309358.ATL_decision_tree(en-us).jpg"><img src="http://i.msdn.microsoft.com/ee309358.ATL_decision_tree(en-us).jpg" alt="ATL Vulnerability Decision Tree"></a></p>
<p>posted by Charles</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update#c633844075720000000</link>
		<pubDate>Tue, 28 Jul 2009 19:52:52 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update#c633844075720000000</guid>
		<dc:creator>Charles</dc:creator>
	</item>
	<item>
		<title>Re: Inside the Active Template Library (ATL) Security Update</title>
		<description>
			<![CDATA[
<p>thanks</p>
<p>posted by Dook</p>]]>
		</description>
		<link>http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update#c633970321630000000</link>
		<pubDate>Mon, 21 Dec 2009 22:42:43 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Blogs/Charles/Out-of-Band-Inside-the-ATL-Security-Update#c633970321630000000</guid>
		<dc:creator>Dook</dc:creator>
	</item>
</channel>
</rss>