Microsoft makes good on promise of out-of-band patches
Starting with the patches, Microsoft has made a ton of data available, and there is a lot of rumor and speculation about the kill bit bypass vulnerability. The hope is that the vast amounts of data will help administrators and developers alike. (The entire list of information and resources can be found here .)
"The out-of-orchestra release significantly impacts both the MS development community and the IT community. Developers need to update any COM and ActiveX elements of there offerings and problem immediate updates," said Don Leatham of Lumension, adding that IT administrators should patch Internet Explorer apace and review Web applications for ActiveX use.
"If there are any such web applications, the vendor should be contacted immediately to see when a new version of the ActiveX charge that includes todays updates will be available," he said.
MS09-034 is rated critical by Microsoft and aimed at both IT and consumers. MS09-035, rated unexcessive, is aimed primarily at developers and IT, as it addresses the vulnerabilities in Microsoft Visual Studio 2005 and 2008. As mentioned in earlier reports on the out-of-pack patches, MS09-032, released earlier this month, protected against the known attacks.

ITProPortal has been no adduce or reference to fixing the issue in msvidctl.dll itself. They have stated that MS09-034 will 'help screen against exploitation', Patch Critical Visual Studio VulnerabilitiesMicrosoft delivers crisis patches to IE, code libraryMicrosoft issues Active Template Library updatesall 299 information articles »
爱蜂窝1、微软公司已经发布针对该视频“零日”漏洞的补丁程序MS09-032:ActiveX Kill Bit累计安全更新,用户应立即下载安装。 攻击者利用微软“零日漏洞”传播木马[原创]小心 有人利用微软“零日”漏洞传播木马利用微软“零日”漏洞传播木马的攻击者被发现all 243 expos articles »