HTTP: Dangerous Visual Basic Unsafe ActiveX Control Access

This signature detects attempts to exploit a known vulnerability against Visual Basic ActiveX controls. An attacker can create a malicious Web site containing dangerous ActiveX elements, which if accessed by a victim, allows the attacker to take control of the victim's client browser and execute arbitrary code.

Extended Description

Microsoft Hierarchical FlexGrid ActiveX control is prone to a remote memory-corruption vulnerability. Remote attackers can exploit this issue to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Successful exploits will compromise the application and possibly the underlying computer. Failed attacks will cause denial-of-service conditions. Microsoft Hierarchical FlexGrid Control 6.0.88.4 is vulnerable; other versions may also be affected. The control is bundled with Microsoft Visual Basic 6.0 and Microsoft Visual FoxPro 8.0 SP1 and 9.0 SP 2.

Affected Products

Microsoft visual_foxpro

Short Name
HTTP:STC:ACTIVEX:VISBASIC6-AX-1
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access ActiveX Basic CVE-2008-3704 CVE-2008-4253 CVE-2008-4254 CVE-2008-4255 CVE-2009-0305 Control Dangerous Unsafe Visual bid:30674 bid:32612 bid:33663
Release Date
12/09/2008
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3725
False Positive
Unknown
Vendors

Microsoft

CVSS Score

9.3

8.5

Found a potential security threat?