Launch Printer Friendly Page Security TechCenter > Security Advisories > Microsoft Security Advisory (969898)

Microsoft Security Advisory (969898)

Update Rollup for ActiveX Kill Bits

Published: | Updated:

Version: 1.1

Microsoft is releasing a new set of ActiveX kill bits with this advisory.

The update includes a kill bit from a previously published Microsoft Cumulative Update:

The update also includes kill bits for the following third-party software:

  • Microgaming. This security update sets a kill bit for an ActiveX control developed by Microgaming. Microgaming has released a security update that addresses a vulnerability in the affected component. For more information and download locations, see the security release from Microgaming. This kill bit is being set at the request of the owner of the ActiveX controls. The class identifiers (CLSIDs) for this ActiveX control are as listed in the Frequently Asked Questions section of this advisory.
  • eBay Advanced Image Upload Component. This security update sets a kill bit for an ActiveX control developed by eBay. eBay has released a security update that addresses a vulnerability in the affected component. For more information and download locations, see the security release from eBay. This kill bit is being set at the request of the owner of the ActiveX controls. The class identifiers (CLSIDs) for this ActiveX control are as listed in the Frequently Asked Questions section of this advisory.
  • HP Virtual Room v7.0. This security update sets a kill bit for an ActiveX control developed by Hewlett-Packard (HP). HP has released a security update that addresses a vulnerability in the affected component. For more information and download locations, see the security release from HP. This kill bit is being set at the request of the owner of the ActiveX controls. The class identifiers (CLSIDs) for this ActiveX control are as listed in the Frequently Asked Questions section of this advisory.

For more information about installing this update, see Microsoft Knowledge Base Article 969898.

General Information

Overview

Frequently Asked Questions

Suggested Actions

Other Information

Acknowledgments

Microsoft thanks the following for working with us to help protect customers:

  • Robert Freeman of ISS X-Force for reporting the MSCOMM32.OCX ATL Loader Remote Code Execution Vulnerability (CVE-2008-0024)

Resources:

Disclaimer:

The information provided in this advisory is provided "as is" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.

Revisions:

  • V1.0 (June 9, 2009): Advisory published
  • V1.1 (June 17, 2009): Added an entry to Frequently Asked Questions to communicate that for the purpose of automatic updating, this update does not replace the Cumulative Security Update of ActiveX Kill Bits (950760) that is described in Microsoft Security Bulletin MS08-032.