Vulnerability record · CVE-2008-0659 · published 8 February 2008
CVE-2008-0659: Aurigma Image Uploader ActiveX Control Stack Buffer Overflow
Aurigma · Image Uploader Activex Control
The Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, also shipped as MySpace MySpaceUploader.ocx 1.0.0.4, contains a stack-based buffer overflow reachable through a long Action property. Because the control is instantiated in the browser, a remote attacker can trigger memory corruption and execute arbitrary code in the context of the victim's browser process.
Description
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote code execution with complete impact and has public exploit code, but it affects a legacy ActiveX control that is no longer widely deployed.
What it is
The Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, also shipped as MySpace MySpaceUploader.ocx 1.0.0.4, contains a stack-based buffer overflow reachable through a long Action property. Because the control is instantiated in the browser, a remote attacker can trigger memory corruption and execute arbitrary code in the context of the victim's browser process.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the user running the browser, allowing full compromise of the workstation. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
Reached over the network by a web page that instantiates the vulnerable ActiveX control and sets an oversized Action property; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required. User interaction is implied because the victim must load the malicious page in a browser that permits the control to run, though the record does not state this explicitly.
Exploitation
The control is not listed in CISA KEV, but EPSS is high (0.56343, 99th percentile) and a SecurityFocus reference is tagged Exploit with a public Exploit-DB entry (5025), indicating public exploit code exists.
What to do
- Apply the vendor fix or upgrade the Aurigma Image Uploader ActiveX control past 4.5.70 and the MySpace MySpaceUploader.ocx past 1.0.0.4.
- Remove or unregister ImageUploader4.ocx and MySpaceUploader.ocx where the upload functionality is not required.
- Enforce ActiveX kill-bit settings for the affected CLSIDs to block instantiation in Internet Explorer.
- Restrict browsing with legacy ActiveX-capable browsers and block untrusted sites from loading the control.
- Monitor vendor and CERT/CC advisories for updated guidance on the affected control.
Detection
- Search endpoints for ImageUploader4.ocx and MySpaceUploader.ocx and record their file versions.
- Monitor browser and process telemetry for unexpected child processes spawned by iexplore.exe or other hosts loading the control.
- Review proxy and web logs for pages that reference the vulnerable ActiveX control or its CLSID.
- Alert on crash reports or memory-corruption events tied to the affected OCX modules.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-0659 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-0659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.