CVE-2007-2884

Microsoft Visual Basic 6 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-2884. PoCs published by UmZ.

AI-analyzed exploit summary This exploit generates a malformed Visual Basic 6 project file with an overly long 'Description' field (1037690 characters) to trigger a stack overflow in the VB6 IDE. The PoC demonstrates a DoS and potential privilege escalation via SEH-based exploitation.

Description

Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Name (VersionCompanyName) field.

Exploits (2)

exploitdb WORKING POC VERIFIED
by UmZ · perldoswindows
https://www.exploit-db.com/exploits/3977

This exploit generates a malformed Visual Basic 6 project file with an overly long 'Description' field (1037690 characters) to trigger a stack overflow in the VB6 IDE. The PoC demonstrates a DoS and potential privilege escalation via SEH-based exploitation.

Classification
Working Poc 90%
Attack Type
Dos | Lpe
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Visual Basic 6.0 IDE
No auth needed
Prerequisites: Local access to a system with Visual Basic 6.0 IDE installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by UmZ · perldoswindows
https://www.exploit-db.com/exploits/3976

This Perl script generates a malformed Visual Basic 6 project file that exploits a stack overflow vulnerability in the 'Company Name' field, leading to a DoS condition with 100% CPU usage. The exploit crafts a .vbp file with an excessively long 'VersionCompanyName' field to trigger the vulnerability.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Visual Basic 6
No auth needed
Prerequisites: Local access to the system · Visual Basic 6 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41053
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34475
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3977
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/41052
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3976
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24128
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34476
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24129

Scores

EPSS 0.3622
EPSS Percentile 98.3%

Details

CWE
CWE-20 CWE-399
Status published
Products (1)
microsoft/visual_basic 6.0
Published May 30, 2007
Tracked Since Feb 18, 2026