PT-2008-5540 · Microsoft · Visual Studio .Net 2003+4

Michal Bucko

·

Published

2008-12-10

·

Updated

2018-10-12

·

CVE-2008-4256

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Visual Basic 6.0 Microsoft Visual Studio .NET 2002 SP1 Microsoft Visual Studio .NET 2003 SP1 Microsoft Visual FoxPro 8.0 SP1 Microsoft Visual FoxPro 9.0 SP1 Microsoft Visual FoxPro 9.0 SP2
Description: The issue is related to the Charts ActiveX control, which does not properly handle errors during access to incorrectly initialized objects. This allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the system state.
Recommendations: For Microsoft Visual Basic 6.0, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual Studio .NET 2002 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual Studio .NET 2003 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual FoxPro 8.0 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual FoxPro 9.0 SP1, update to a version that includes the fix for the Charts Control Memory Corruption issue. For Microsoft Visual FoxPro 9.0 SP2, update to a version that includes the fix for the Charts Control Memory Corruption issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4256

Affected Products

Visual Basic 6.0
Visual Foxpro 8.0
Visual Foxpro 9.0
Visual Studio .Net 2002
Visual Studio .Net 2003