CVE-2009-0901 describes a critical vulnerability in the Active Template Library (ATL) across various Microsoft Visual Studio and Windows versions. This flaw allows remote attackers to execute arbitrary code by sending a malformed stream to an ATL component or control, due to improper handling of uninitialized VARIANT objects during VariantClear calls. With a CVSS score of 9.3, this vulnerability is highly severe, requiring no authentication and having a medium attack complexity, but leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in the KEV catalog, and it has received no community discussion or media coverage, suggesting it is not actively exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2005CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_c\+\+:2005:sp1_redistribution_pkg:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_c\+\+:2008:redistribution_pkg:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_c\+\+:2008:sp1_redistribution_pkg:*:*:*:*:*:* | ||
2005CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio:2005:sp1:*:*:*:*:*:* | ||
2005CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio:2005:sp1:64_bit_hosted_visual_c\+\+_tools:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.