|
|
| |
| |
CERT-In Vulnerability Note
CIVN-2008-0183
Multiple Vulnerabilities Microsoft Visual Basic ActiveX Controls
Original Issue Date:December 11, 2008
Severity Rating: HIGH
Systems Affected
- Microsoft Visual Basic 6.0 SP6 and prior
- Microsoft Visual FoxPro 8.0 SP1 and prior
- Microsoft Visual FoxPro 9.0 SP2 and prior
- Microsoft Office FrontPage 2002 SP3 and prior
- Microsoft Office Project 2003 SP3 and prior
- Microsoft Visual Studio .NET 2002 SP1 and prior
- Microsoft Visual Studio .NET 2003 SP1 and prior
- Microsoft Office Project 2003 SP3 and prior
- Microsoft Office Project 2007 SP1 and prior
Overview
Multiple vulnerabilities have been reported in various Microsoft products, which can be exploited by malicious people to compromise a user's system.
An unauthenticated, remote attacker could exploit these vulnerabilities by convincing a user to visit a website that is designed to invoke the ActiveX control in a malicious manner. If successful, the attacker could execute arbitrary code with the privileges of the user.
Description
1. DataGrid Control Memory Corruption Vulnerability
(
CVE-2008-4252
)
The vulnerability is due to an error in the DataGrid ActiveX control when handling uninitialized objects. An exploit could cause the control to access uninitialized memory objects, resulting in an exploitable memory corruption error and allowing the attacker to execute arbitrary code with the privileges of the user who launched the browser.
2. FlexGrid Control Memory Corruption Vulnerability
(
CVE-2008-4253
)
The vulnerability exists due to unsafe memory operations on uninitalized memory objects. The Visual Basic FlexGrid ActiveX control may attempt to access previously freed or uninitialized memory areas as a result of processing malformed data.
3. Hierarchical FlexGrid Control Memory Corruption Vulnerability
(
CVE-2008-4254
)
The vulnerability is due to unsafe operations on uninitialized memory objects. When processing malformed data, the Hierarchical FlexGrid ActiveX control supplied with Visual Basic may attempt to access memory areas that have been freed or are uninitialized.
4. Windows Common Control Memory Corruption Vulnerability
(
CVE-2008-4255
)
This vulnerability exists due to improper processing of AVI files by the Windows Common ActiveX control.
5. Charts Control Memory Corruption Vulnerability
(
CVE-2008-4256
)
This vulnerability exists due to improper processing of user-supplied input by the Visual Basic Charts ActiveX control. The attacker could leverage the memory corruption to execute arbitrary code with the privileges of the user.
6. Masked Edit Control Memory Corruption Vulnerability
(
CVE-2008-3704
)
This vulnerability exists due to an error by the Masked Edit ActiveX control Msmask32.ocx . Msmask32.ocx does not properly validate user-supplied input that is passed to the Mask parameter.
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
CERT-IN - Computer Emergency Response Team - Page Requested Currently Not available
| | | |