Vulnerability record · CVE-2008-3704 · published 18 August 2008
CVE-2008-3704: Microsoft MaskedEdit ActiveX control heap buffer overflow
Microsoft · Visual Basic
The MaskedEdit ActiveX control in Msmask32.ocx fails to validate the Mask property with boundary checks, causing a heap-based buffer overflow when a long Mask value is supplied. It affects Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1/SP2, and was exploited in the wild in August 2008.
Description
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a 9.3 CVSS score and confirmed in-the-wild exploitation, though the affected products are legacy and the flaw dates to 2008.
What it is
The MaskedEdit ActiveX control in Msmask32.ocx fails to validate the Mask property with boundary checks, causing a heap-based buffer overflow when a long Mask value is supplied. It affects Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1/SP2, and was exploited in the wild in August 2008.
Impact
A remote attacker can execute arbitrary code in the context of the user who loads the control, giving full compromise of confidentiality, integrity and availability. The CVSS 2.0 score is 9.3 (HIGH).
Attack surface
Reached over the network (AV:N) by a victim visiting a crafted web page or opening a document that instantiates the ActiveX control; no authentication is required (Au:N), but some user interaction is needed to load the page or file (AC:M).
Exploitation
The description states the flaw was exploited in the wild in August 2008, and reference tags include Exploit and Patch; the CVE is not listed in CISA KEV, while EPSS is 0.55917 (99th percentile).
What to do
- Apply Microsoft security bulletin MS08-070, which updates Msmask32.ocx to version 6.0.84.18 or later.
- Set the kill bit for the MaskedEdit ActiveX control (CLSID) in Internet Explorer where the control is not required.
- Restrict or block ActiveX control execution in browsers and email clients, and disable ActiveX in untrusted zones.
- Remove or unregister Msmask32.ocx on systems that do not need Visual Basic 6.0, Visual Studio, or Visual FoxPro development components.
- Audit hosts for the affected development products and prioritize patching internet-facing or user-workstation systems.
Detection
- Search for Msmask32.ocx file versions below 6.0.84.18 across endpoints.
- Monitor for processes loading Msmask32.ocx, especially browser or Office processes, and for unexpected child processes spawned from them.
- Check registry for the MaskedEdit control kill-bit setting and alert on its removal or absence where policy requires it.
- Review web proxy and IDS logs for known exploit URLs or payloads associated with the MaskedEdit control.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-3704 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-3704), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.