PT-2008-5540 · Microsoft · Visual Studio .Net 2003+4

Michal Bucko

·

Publicado

2008-12-10

·

Atualizado

2018-10-12

·

CVE-2008-4256

CVSS v2.0

8.5

Alta

VetorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Visual Basic 6.0 Microsoft Visual Studio .NET 2002 SP1 Microsoft Visual Studio .NET 2003 SP1 Microsoft Visual FoxPro 8.0 SP1 Microsoft Visual FoxPro 9.0 SP1 Microsoft Visual FoxPro 9.0 SP2
Description: The issue is related to the Charts ActiveX control, which does not properly handle errors during access to incorrectly initialized objects. This allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the system state.
Recommendations: For Microsoft Visual Basic 6.0, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual Studio .NET 2002 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual Studio .NET 2003 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual FoxPro 8.0 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual FoxPro 9.0 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual FoxPro 9.0 SP2, update to a version that includes the fix for the Charts Control Memory Corruption issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4256

Produtos afetados

Visual Basic 6.0
Visual Foxpro 8.0
Visual Foxpro 9.0
Visual Studio .Net 2002
Visual Studio .Net 2003