First published: Wed Dec 10 2008(Updated: )
The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "Charts Control Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Visual FoxPro | =9.0-sp2 | |
Microsoft Visual Studio | =2003-sp1 | |
Microsoft Visual Studio | =2002-sp1 | |
Microsoft Visual FoxPro | =8.0-sp1 | |
Microsoft Visual Basic SDK | =6.0 | |
Microsoft Project 2013 | =2003-sp3 | |
Microsoft Office FrontPage | =2002-sp3 | |
Microsoft Visual FoxPro | =9.0-sp1 | |
Microsoft Project 2013 | =2007-sp1 | |
Microsoft Project 2013 | =2007 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4256 is rated as critical due to its potential to allow remote code execution.
To fix CVE-2008-4256, update to the latest security patch provided by Microsoft for the affected software versions.
CVE-2008-4256 affects Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2.
CVE-2008-4256 is a remote code execution vulnerability caused by improper handling of incorrectly initialized objects.
Remote attackers can exploit CVE-2008-4256 through crafted HTML content targeting the affected applications.