← Vulnerability feed

Vulnerability record · CVE-2008-2551 · published 4 June 2008

CVE-2008-2551: Icona C6 Messenger ActiveX control allows forced download and execution of arbitrary files

Icona · Instant Messenger

The DownloaderActiveX Control (DownloaderActiveX.ocx) shipped with Icona SpA C6 Messenger 1.0.0.1 accepts a URL in the propDownloadUrl parameter and, when propPostDownloadAction is set to "run," downloads and executes the referenced file. This lets a remote attacker turn a web page into a file-delivery and execution channel on any host running the vulnerable control, with no credentials required.

9.3 CVSS 2.0 High EPSS 47% · top 1.2% CWE-264 · Permissions and access controls
9.3CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw yields unauthenticated remote code execution with a public exploit and high EPSS score, but it is confined to an old, likely rare third-party messenger client and requires the victim to load a malicious page.

What it is

The DownloaderActiveX Control (DownloaderActiveX.ocx) shipped with Icona SpA C6 Messenger 1.0.0.1 accepts a URL in the propDownloadUrl parameter and, when propPostDownloadAction is set to "run," downloads and executes the referenced file. This lets a remote attacker turn a web page into a file-delivery and execution channel on any host running the vulnerable control, with no credentials required.

Impact

An attacker gains arbitrary code execution in the context of the logged-on user, which typically means full control of the workstation and any credentials or data reachable from it.

Attack surface

Reached over the network through a malicious or compromised web page that instantiates the ActiveX control in the victim's browser; no authentication is needed, but the victim must load the page and the control must be permitted to run, so some user interaction is implied by the AV:N/AC:M vector.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but a public Exploit-DB entry (5732) exists and EPSS gives a 30-day probability of roughly 0.47 (98.8th percentile), indicating meaningful real-world exploitation likelihood.

What to do

  • Apply the vendor fix or remove/unregister DownloaderActiveX.ocx if Icona C6 Messenger is not required; the product appears abandoned, so removal is the safer path.
  • Kill or block the CLSID for DownloaderActiveX.ocx via Internet Explorer's ActiveX kill-bit mechanism and restrict ActiveX installation and execution through browser policy.
  • Enforce allowlisting or blocking of outbound downloads and execution from browser processes so a downloaded payload cannot run.
  • Retire or isolate hosts still running C6 Messenger 1.0.0.1, since no supported patched version is identified in this record.

Detection

  • Search endpoint inventories and registry for DownloaderActiveX.ocx or its CLSID to find hosts with the control installed.
  • Monitor browser and child-process telemetry for a browser spawning executables from temporary download directories.
  • Alert on HTTP responses that deliver executable content to browser sessions on hosts where the control is present.
  • Review proxy and DNS logs for downloads initiated by C6 Messenger or its ActiveX host process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-2551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2008-2551), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.