PT-2008-5538 · Microsoft · Visual Basic 6.0+2

Carsten Eiram

+1

·

Published

2008-12-10

·

Updated

2018-10-12

·

CVE-2008-4254

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Visual Basic 6.0 Microsoft Visual FoxPro versions 8.0 SP1 through 9.0 SP2
Description: The issue is related to multiple integer overflows in the Hierarchical FlexGrid ActiveX control, which allows remote attackers to execute arbitrary code. This is achieved by crafting specific properties, such as Rows and Cols, to the ExpandAll and CollapseAll methods. The exploitation is linked to the access of incorrectly initialized objects and the corruption of the system state.
Recommendations: For Microsoft Visual Basic 6.0, update to a version that includes the fix for the Hierarchical FlexGrid Control Memory Corruption issue. For Microsoft Visual FoxPro versions 8.0 SP1 through 9.0 SP2, update to a version that includes the fix for the Hierarchical FlexGrid Control Memory Corruption issue. As a temporary workaround, consider restricting access to the Hierarchical FlexGrid ActiveX control until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4254

Affected Products

Hierarchical Flexgrid Activex Control
Visual Basic 6.0
Visual Foxpro