PT-2008-5538 · Microsoft · Visual Basic 6.0+2

Carsten Eiram

+1

·

Publicado

2008-12-10

·

Atualizado

2018-10-12

·

CVE-2008-4254

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Visual Basic 6.0 Microsoft Visual FoxPro versions 8.0 SP1 through 9.0 SP2
Description: The issue is related to multiple integer overflows in the Hierarchical FlexGrid ActiveX control, which allows remote attackers to execute arbitrary code. This is achieved by crafting specific properties, such as Rows and Cols, to the ExpandAll and CollapseAll methods. The exploitation is linked to the access of incorrectly initialized objects and the corruption of the system state.
Recommendations: For Microsoft Visual Basic 6.0, update to a version that includes the fix for the Hierarchical FlexGrid Control Memory Corruption issue. For Microsoft Visual FoxPro versions 8.0 SP1 through 9.0 SP2, update to a version that includes the fix for the Hierarchical FlexGrid Control Memory Corruption issue. As a temporary workaround, consider restricting access to the Hierarchical FlexGrid ActiveX control until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4254

Produtos afetados

Hierarchical Flexgrid Activex Control
Visual Basic 6.0
Visual Foxpro