Looks like the folks on the MSRC blog just posted the August security bulleting webcast and customer Q&A. To quote their site:
It is apparent that there is still a bit of confusion around the Active Template Library (ATL) issue and how current updates relate to work we have already done to provide mitigations, protections and guidance to customers. To try and provide some clarity:
To be even clearer, not every ActiveX control is vulnerable and we have an ongoing investigation into this issue. We will continue to provide updates via Security Advisory 973882 and Security Bulletins as necessary.
Of course this is not the only issue we addressed this month and customers had quite a few questions during the webcast that we provided answers and guidance for.
For more information and to view the webcast and Q&A see http://blogs.technet.com/msrc/archive/2009/08/14/august-2009-security-bulletin-webcast-video-and-customer-q-a.aspx
Enjoy!
J.C. Hornbeck | Manageability Knowledge Engineer