Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
BID:32592
Info
Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
| Bugtraq ID: | 32592 |
| Class: | Unknown |
| CVE: |
CVE-2008-4253 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2008 12:00AM |
| Updated: | Feb 10 2009 09:48PM |
| Credit: | ADLab of VenusTech |
| Vulnerable: |
Microsoft Visual FoxPro 9.0 SP2 Microsoft Visual FoxPro 9.0 SP1 Microsoft Visual FoxPro 8.0 SP1 Microsoft Visual Basic 6.0 Microsoft Project 2003 SP3 Microsoft Project 2003 SP2 Microsoft Project 2003 SP1 Microsoft Project 2003 Microsoft FrontPage 2002 SP3 Microsoft FrontPage 2002 SP1 Microsoft FrontPage 2002 |
| Not Vulnerable: | |
Discussion
Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
Microsoft FlexGrid ActiveX control is prone to a remote memory-corruption vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft FlexGrid ActiveX control is prone to a remote memory-corruption vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
Solution:
The vendor has released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Visual FoxPro 8.0 SP1
Microsoft Visual FoxPro 9.0 SP1
Microsoft Visual FoxPro 9.0 SP2
Microsoft Project 2003 SP3
Microsoft Visual Basic 6.0
Microsoft FrontPage 2002 SP3
Solution:
The vendor has released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Visual FoxPro 8.0 SP1
-
Microsoft Visual FoxPro 8.0 SP1 ActiveX Controls Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=A6977F81-F7F6 -486B-96AD-8D296D79F205
Microsoft Visual FoxPro 9.0 SP1
-
Microsoft Visual FoxPro 9.0 SP1 ActiveX Controls Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=386D27A6-B2C7 -4ACC-BF3E-EDCBC7358172
Microsoft Visual FoxPro 9.0 SP2
-
Microsoft Visual FoxPro 9.0 SP2 ActiveX Controls Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=5B1F28A9-DA8D -463A-8AE4-DFC8FCC6C41A
Microsoft Project 2003 SP3
-
Microsoft Security Update for Microsoft Office Project 2003 (KB949045)
http://www.microsoft.com/downloads/details.aspx?familyid=89a44042-a629 -40f3-800a-0bb45fc36591
Microsoft Visual Basic 6.0
-
Microsoft Microsoft Visual Basic 6.0 Service Pack 6 Cumulative Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=CB824E35-0403 -45C4-9E41-459F0EB89E36 -
Microsoft Microsoft Visual Basic 6.0 Service Pack 6 Security Rollup Update
http://www.microsoft.com/downloads/details.aspx?familyid=E27EEBCB-095D -43EC-A19E-4A46E591715C
Microsoft FrontPage 2002 SP3
-
Microsoft Security Update for Microsoft Office XP (KB957797)
http://www.microsoft.com/downloads/details.aspx?familyid=0a6130ae-c5b4 -43cb-afe3-ab6a55b9d9ea
References
Microsoft FlexGrid ActiveX Control Memory Corruption Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Advisory 960715 (Microsoft)
- Microsoft Security Bulletin MS08-070 (Microsoft)