CVE-2008-3704

EXPLOITED IN THE WILD

Microsoft Visual Studio <6.0.84.18 - Buffer Overflow

Title source: llm

Description

Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16507
exploitdb WORKING POC VERIFIED
by Koshi · htmlremotewindows
https://www.exploit-db.com/exploits/6317
exploitdb WORKING POC VERIFIED
by Symantec · javascriptdoswindows
https://www.exploit-db.com/exploits/6244
metasploit WORKING POC NORMAL
by Symantec, koshi, MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms08_070_visual_studio_msmask.rb

Scores

EPSS 0.8747
EPSS Percentile 99.5%

Details

VulnCheck KEV 2008-08-18
InTheWild.io 2018-10-12
CWE
CWE-119
Status published
Products (6)
microsoft/visual_basic 6.0
microsoft/visual_foxpro 8.0 sp1
microsoft/visual_foxpro 9.0 sp1 (2 CPE variants)
microsoft/visual_studio 6.0
microsoft/visual_studio_.net 2002 sp1
microsoft/visual_studio_.net 2003 sp1
Published Aug 18, 2008
Tracked Since Feb 18, 2026