Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Overflow Vulnerability
BID:32613
Info
Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Overflow Vulnerability
| Bugtraq ID: | 32613 |
| Class: | Unknown |
| CVE: |
CVE-2008-4255 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2008 12:00AM |
| Updated: | Apr 19 2013 02:39AM |
| Credit: | Mark Dowd, working with McAfee Avert Labs, Brett Moore of Security Assessment, and CHkr_D591, working with TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Microsoft Visual Studio .NET 2003 SP1 Microsoft Visual Studio .NET 2003 Microsoft Visual Studio .NET 2002 SP1 Microsoft Visual Studio .NET 2002 Microsoft Visual FoxPro 9.0 SP2 Microsoft Visual FoxPro 9.0 SP1 Microsoft Visual FoxPro 8.0 SP1 Microsoft Visual Basic 6.0 Microsoft Project Standard 2007 SP 1 Microsoft Project Standard 2007 0 Microsoft Project Professional 2007 SP 1 Microsoft Project Professional 2007 0 Microsoft Project 2003 SP3 Microsoft Project 2003 SP2 Microsoft Project 2003 SP1 Microsoft Project 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Overflow Vulnerability
Microsoft Windows Common AVI ActiveX control is prone to a remote buffer-overflow vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Microsoft Windows Common AVI ActiveX control is prone to a remote buffer-overflow vulnerability.
Remote attackers can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Overflow Vulnerability
A proof of concept is available. Note that converting this proof of concept into functional exploit code should be trivial.
A proof of concept is available. Note that converting this proof of concept into functional exploit code should be trivial.
Solution / Fix
Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Project Standard 2007 SP 1
Microsoft Visual FoxPro 8.0 SP1
Microsoft Visual FoxPro 9.0 SP1
Microsoft Visual Studio .NET 2003 SP1
Microsoft Visual FoxPro 9.0 SP2
Microsoft Project 2003 SP3
Microsoft Visual Basic 6.0
Microsoft Project Professional 2007 0
Microsoft Project Professional 2007 SP 1
Microsoft Project Standard 2007 0
Microsoft Visual Studio .NET 2002 SP1
Solution:
The vendor has released an advisory and updates to address this issue. Please see the references for more information.
Microsoft Project Standard 2007 SP 1
-
Microsoft Security Update for Microsoft Office Project 2007 (KB949046)
http://www.microsoft.com/downloads/details.aspx?familyid=2fbf6a5b-ff35 -4a2d-9fa0-4e62b6486fe6
Microsoft Visual FoxPro 8.0 SP1
-
Microsoft Visual FoxPro 8.0 SP1 ActiveX Controls Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=A6977F81-F7F6 -486B-96AD-8D296D79F205
Microsoft Visual FoxPro 9.0 SP1
-
Microsoft Visual FoxPro 9.0 SP1 ActiveX Controls Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=386D27A6-B2C7 -4ACC-BF3E-EDCBC7358172
Microsoft Visual Studio .NET 2003 SP1
-
Microsoft Visual Studio .NET 2003 Service Pack 1 ActiveX Controls Security Update Rollup
http://www.microsoft.com/downloads/details.aspx?familyid=6AC7CF8F-D046 -43A8-B4EF-253153D65AED
Microsoft Visual FoxPro 9.0 SP2
-
Microsoft Visual FoxPro 9.0 SP2 ActiveX Controls Security Update
http://www.microsoft.com/downloads/details.aspx?familyid=5B1F28A9-DA8D -463A-8AE4-DFC8FCC6C41A
Microsoft Project 2003 SP3
-
Microsoft Security Update for Microsoft Office Project 2003 (KB949045)
http://www.microsoft.com/downloads/details.aspx?familyid=89a44042-a629 -40f3-800a-0bb45fc36591
Microsoft Visual Basic 6.0
-
Microsoft Microsoft Visual Basic 6.0 Service Pack 6 Cumulative Update
http://www.microsoft.com/downloads/details.aspx?FamilyId=CB824E35-0403 -45C4-9E41-459F0EB89E36 -
Microsoft Microsoft Visual Basic 6.0 Service Pack 6 Security Rollup Update
http://www.microsoft.com/downloads/details.aspx?familyid=E27EEBCB-095D -43EC-A19E-4A46E591715C
Microsoft Project Professional 2007 0
-
Microsoft Security Update for Microsoft Office Project 2007 (KB949046)
http://www.microsoft.com/downloads/details.aspx?familyid=2fbf6a5b-ff35 -4a2d-9fa0-4e62b6486fe6
Microsoft Project Professional 2007 SP 1
-
Microsoft Security Update for Microsoft Office Project 2007 (KB949046)
http://www.microsoft.com/downloads/details.aspx?familyid=2fbf6a5b-ff35 -4a2d-9fa0-4e62b6486fe6
Microsoft Project Standard 2007 0
-
Microsoft Security Update for Microsoft Office Project 2007 (KB949046)
http://www.microsoft.com/downloads/details.aspx?familyid=2fbf6a5b-ff35 -4a2d-9fa0-4e62b6486fe6
Microsoft Visual Studio .NET 2002 SP1
-
Microsoft Visual Studio .NET 2002 Service Pack 1 Security Update Rollup
http://www.microsoft.com/downloads/details.aspx?familyid=AFAD980D-7F27 -49D9-AA23-B762C7B94CD6
References
Microsoft Windows Common AVI ActiveX Control File Parsing Buffer Overflow Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- ZDI-08-083: Microsoft Animation ActiveX Control Malformed AVI Parsing Code Execu ([email protected])
- Microsoft Security Advisory 960715 (Microsoft)
- Microsoft Security Bulletin MS08-070 (Microsoft)
- ZDI-08-083 Microsoft Animation ActiveX Control Malformed AVI Parsing Code Execut (ZDI)