CVE-2009-2495
published 2009-07-29CVE-2009-2495: The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold…
PriorityP344medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
34.30%
98.2th percentile
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_c | — | — |
| microsoft | visual_c | — | — |
| microsoft | visual_studio | — | — |
| microsoft | visual_studio | — | — |
| microsoft | visual_studio_net | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Visual Studio 2005 information disclosure (Nessus ID 40421 / ID 116529)
vuldb·2026-05-27·CVSS 6.5
CVE-2009-2495 [MEDIUM] Microsoft Visual Studio 2005 information disclosure (Nessus ID 40421 / ID 116529)
A vulnerability, which was classified as problematic, has been found in Microsoft Visual Studio 2005. Impacted is an unknown function. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2009-2495. The attack is possible to be carried out remotely. No exploit exists.
GHSA
GHSA-w98q-7wf3-vg43: The Active Template Library (ATL) in Microsoft Visual Studio
ghsa_unreviewed·2022-05-02
CVE-2009-2495 [HIGH] CWE-200 GHSA-w98q-7wf3-vg43: The Active Template Library (ATL) in Microsoft Visual Studio
The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=126592505426855&w=2http://secunia.com/advisories/35967http://secunia.com/advisories/36374http://secunia.com/advisories/36746http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1http://www.adobe.com/support/security/bulletins/apsb09-10.htmlhttp://www.adobe.com/support/security/bulletins/apsb09-13.htmlhttp://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1http://www.us-cert.gov/cas/techalerts/TA09-195A.htmlhttp://www.us-cert.gov/cas/techalerts/TA09-286A.htmlhttp://www.vupen.com/english/advisories/2009/2034https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-035https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-060https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6305https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6478https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7573http://marc.info/?l=bugtraq&m=126592505426855&w=2http://secunia.com/advisories/35967http://secunia.com/advisories/36374http://secunia.com/advisories/36746http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1http://www.adobe.com/support/security/bulletins/apsb09-10.htmlhttp://www.adobe.com/support/security/bulletins/apsb09-13.htmlhttp://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1http://www.us-cert.gov/cas/techalerts/TA09-195A.htmlhttp://www.us-cert.gov/cas/techalerts/TA09-286A.htmlhttp://www.vupen.com/english/advisories/2009/2034https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-035https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-060https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6305https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6478https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7573
2009-07-29
Published