Vulnerability record · CVE-2007-4790 · published 10 September 2007
CVE-2007-4790: Microsoft Visual FoxPro ActiveX control stack buffer overflow via FoxDoCmd
Microsoft · Internet Explorer
A stack-based buffer overflow exists in the FPOLE.OCX 6.0.8450.0 and Foxtlib.ocx ActiveX controls shipped with the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library. Passing an overly long first argument to the FoxDoCmd function overflows a stack buffer, and the control can be instantiated in Internet Explorer 5.01, 6 SP1/SP2 and 7, so a web page can trigger the flaw in a browsing session.
Description
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arbitrary code via a long first argument to the FoxDoCmd function.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution reachable through a browser with public exploit code and very high EPSS, though it requires user interaction and affects legacy software.
What it is
A stack-based buffer overflow exists in the FPOLE.OCX 6.0.8450.0 and Foxtlib.ocx ActiveX controls shipped with the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library. Passing an overly long first argument to the FoxDoCmd function overflows a stack buffer, and the control can be instantiated in Internet Explorer 5.01, 6 SP1/SP2 and 7, so a web page can trigger the flaw in a browsing session.
Impact
An attacker who triggers the overflow can execute arbitrary code in the context of the user running Internet Explorer, giving full control of the affected workstation.
Attack surface
Reached over the network by luring a user to a malicious or compromised web page that instantiates the vulnerable ActiveX control; no authentication is required, but user interaction (visiting the page and allowing the control to load) is needed.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.549, ~99th percentile) and a public exploit reference exists (SecurityFocus BID 25571 tagged Exploit, plus an Exploit-DB entry), indicating exploit code is publicly available.
What to do
- Apply Microsoft security bulletin MS08-010, which addresses this ActiveX control issue, and confirm the updated control version is installed.
- Disable or kill-bit the FPOLE.OCX and Foxtlib.ocx controls where Visual FoxPro 6.0 runtime is not required.
- Restrict ActiveX execution in Internet Explorer and enforce the highest practical zone security settings for internet content.
- Remove or upgrade the legacy Visual FoxPro 6.0 runtime on systems that no longer need it.
- Block or monitor delivery of the known public exploit payloads at the web gateway and endpoint.
Detection
- Monitor for Internet Explorer processes loading FPOLE.OCX or Foxtlib.ocx, especially from untrusted or temporary paths.
- Hunt for crashes or anomalous child processes spawned by iexplore.exe shortly after ActiveX instantiation.
- Alert on network retrieval of pages or files matching known exploit signatures for this FoxDoCmd overflow.
- Audit endpoints for the presence and version of FPOLE.OCX 6.0.8450.0 and Foxtlib.ocx to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4790 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4790), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.