Affected Products
=================
Vulnerable Products
+------------------
The following products are affected by this vulnerability:
* Cisco Unity 4.x, 5x., and 7.x
Products Confirmed Not Vulnerable
+--------------------------------
The following Cisco products are not known to be affected by this
vulnerability:
* Cisco AnyConnect VPN Client
* Cisco Adaptive Security Device Manager (ASDM)
* Cisco Building Broadband Service Manager (BBSM)
* Cisco Catalyst Operating System (Catalyst OS)
* Cisco Computer Telephony Integration Object Server (CTI)
* Cisco IOS Software
* Cisco IP/TV
* Cisco Meetingplace
* Cisco Mobile Wireless Fault Mediator (MWFM)
* Cisco NAC Appliance (formerly Cisco Clean Access)
* Cisco Secure Access Control Server (ACS)
* Cisco Secure Desktop
* Cisco Security Agent
* Cisco Security Monitoring, Analysis and Response System (MARS)
* Cisco SSL VPN Client (SVC)
* Cisco Unified Contact Center Express (Unified CCX)
* Cisco Video Surveillance Media Server (VSMS)
* CiscoWorks LAN Management Solution (LMS)
* WebEx
Details
=======
Microsoft has identified vulnerabilities in the Active Template Library (ATL) headers that are shipped with the Software Development Kit (SDK) for Microsoft Windows systems and used in Cisco products.
In general, this vulnerability, if exposed by an ActiveX control, could lead to remote code execution on a client's system.
For complete details, please review the Microsoft Security Bulletin
at: