Update Protection against Microsoft Visual Studio ActiveX Control Buffer Overflow Vulnerability (MS08-070)
| Check Point Reference: | CPAI-2008-234 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS08-070 | |
| Industry Reference(s): | CVE-2008-3704 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Visual Studio 6.0 | ||
| Vulnerability Description A buffer overflow vulnerability was reported in MS Visual Studio 6.0. Microsoft Visual Studio 6.0 is designed for building Windows based applications and Web solutions. Microsoft Visual Studio 6.0 is shipped with a set of ActiveX controls. The vulnerability is due to a boundary error while handling an overly large parameter of one of the ActiveX controls. A remote attacker could exploit the vulnerability by enticing the target user to visit a malicious web page. Successful exploitation would result in arbitrary code execution. |
||
|
Vulnerability Status It has been observed that active exploits exist in the wild. Note that to exploit this issue, an attacker must entice a user to open a malicious web document. |
|
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-070 |
|
|
Vulnerability Details The vulnerability is due to a memory corruption error in the Visual Basic MaskedEdit ActiveX control when it fails to properly perform boundary checks on user-supplied input. To trigger this issue, an attacker may create a malicious web page that initiates the vulnerable COM Object. Successful exploitation of this vulnerability allows execution of arbitrary code on the vulnerable system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the vulnerable ActiveX Control. Depending on the traffic mix, activating this protection may result in performance degradation.
In order for the protection to be activated, update your VPN-1/IPS-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.