PT-2008-5538 · Microsoft · Visual Basic 6.0+2
Carsten Eiram
+1
·
Published
2008-12-10
·
Updated
2018-10-12
·
CVE-2008-4254
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Visual Basic 6.0
Microsoft Visual FoxPro versions 8.0 SP1 through 9.0 SP2
Description:
The issue is related to multiple integer overflows in the Hierarchical FlexGrid ActiveX control, which allows remote attackers to execute arbitrary code. This is achieved by crafting specific properties, such as
Rows and Cols, to the ExpandAll and CollapseAll methods. The exploitation is linked to the access of incorrectly initialized objects and the corruption of the system state.Recommendations:
For Microsoft Visual Basic 6.0, update to a version that includes the fix for the Hierarchical FlexGrid Control Memory Corruption issue.
For Microsoft Visual FoxPro versions 8.0 SP1 through 9.0 SP2, update to a version that includes the fix for the Hierarchical FlexGrid Control Memory Corruption issue.
As a temporary workaround, consider restricting access to the Hierarchical FlexGrid ActiveX control until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hierarchical Flexgrid Activex Control
Visual Basic 6.0
Visual Foxpro