MS.Visual.Basic.FlexGrid.ActiveX

NameMS.Visual.Basic.FlexGrid.ActiveX.Control.Access
Release DateDec 12, 2008
SeverityHigh
ImpactSystem Compromise.
DescriptionThis indicates an attempt to exploit a memory corruption vulnerability in Microsoft Visual Basic Runtime Extended Files.

The vulnerability is caused by an error that occurs when the FlexGrid ActiveX Control handles specially crafted input. It allows a remote attacker to execute arbitrary code.
Affected ProductsMicrosoft Visual Basic 6.0
Recommended ActionsApply patch:
http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4253
Microsoft Bulletin IDMS08-070   http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx
Reference: VID-16736