CVE-2008-4252: High severity microsoft visual foxpro vulnerability
The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "DataGrid Control Memory Corruption Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4252?
CVE-2008-4252 is rated as critical, allowing remote code execution due to improper error handling.
How do I fix CVE-2008-4252?
To fix CVE-2008-4252, ensure that all affected Microsoft software is updated with the latest security patches.
Which software applications are affected by CVE-2008-4252?
CVE-2008-4252 affects Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1, 9.0 SP1, 9.0 SP2, and various versions of Microsoft Office and Project.
Can CVE-2008-4252 allow an attacker to access local files?
Yes, through remote code execution, CVE-2008-4252 can potentially give attackers access to local files.
What types of attacks can be executed using CVE-2008-4252?
CVE-2008-4252 can be exploited to execute arbitrary code via crafted HTML documents.