IE security update MS09-034 implements two defense-in-depth measures intended to mitigate the threat of attacks which attempt to exploit the Microsoft Active Template Library (ATL) vulnerabilities described in Security Advisory 973882 and MS09-034. We would like to explain these mitigations in more detail.
ATL persisted data checks
The first mitigation is a change to modify how ATL-based controls read persisted data by detecting specific call patterns that are problematic.