Hierarchical FlexGrid Control Memory Corruption Vulnerability
Severity: HIGH
CVE Identifier: MS08-070
Advisory Date: FEB 15, 2011
DESCRIPTION
Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allow remote attackers to execute arbitrary code via crafted (1) Rows and (2) Cols properties to the (a) ExpandAll and (b) CollapseAll methods, related to access of incorrectly initialized objects and corruption of the "system state,"aka "Hierarchical FlexGrid Control Memory Corruption Vulnerability."
TREND MICRO PROTECTION INFORMATION
Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1003125
Trend Micro Deep Security DPI Rule Name: 1003125 - Hierarchical FlexGrid Control Memory Corruption Vulnerability
AFFECTED SOFTWARE AND VERSION
- microsoft office_frontpage 2002
- microsoft project 2007
- microsoft visual_basic 6.0
- microsoft visual_foxpro 8.0
- microsoft visual_foxpro 9.0
- microsoft visual_studio_.net 2002
- microsoft visual_studio_.net 2003