Just look at all troubles that was caused by the latest security fixes to VS-2005/2008/2010
SP and security fixes are installed without asking the developer (maybe even without his knopwledge)
I miss documentation about the impact of such security fixes and how a developer has to care about this.
At least such a security fix should display a warning message box.
Or this fixes should only be installed on demand of the developer.
The developer needs a method to freeze is development tools to s specific version of the CRT/MFC/ATL.