← Vulnerability feed

Vulnerability record · CVE-2008-3704 · published 18 August 2008

CVE-2008-3704: Microsoft MaskedEdit ActiveX control heap buffer overflow

Microsoft · Visual Basic

The MaskedEdit ActiveX control in Msmask32.ocx fails to validate the Mask property with boundary checks, causing a heap-based buffer overflow when a long Mask value is supplied. It affects Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1/SP2, and was exploited in the wild in August 2008.

9.3 CVSS 2.0 High EPSS 56% · top 1.0% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
24References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote code execution with a 9.3 CVSS score and confirmed in-the-wild exploitation, though the affected products are legacy and the flaw dates to 2008.

What it is

The MaskedEdit ActiveX control in Msmask32.ocx fails to validate the Mask property with boundary checks, causing a heap-based buffer overflow when a long Mask value is supplied. It affects Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1/SP2, and was exploited in the wild in August 2008.

Impact

A remote attacker can execute arbitrary code in the context of the user who loads the control, giving full compromise of confidentiality, integrity and availability. The CVSS 2.0 score is 9.3 (HIGH).

Attack surface

Reached over the network (AV:N) by a victim visiting a crafted web page or opening a document that instantiates the ActiveX control; no authentication is required (Au:N), but some user interaction is needed to load the page or file (AC:M).

Exploitation

The description states the flaw was exploited in the wild in August 2008, and reference tags include Exploit and Patch; the CVE is not listed in CISA KEV, while EPSS is 0.55917 (99th percentile).

What to do

  • Apply Microsoft security bulletin MS08-070, which updates Msmask32.ocx to version 6.0.84.18 or later.
  • Set the kill bit for the MaskedEdit ActiveX control (CLSID) in Internet Explorer where the control is not required.
  • Restrict or block ActiveX control execution in browsers and email clients, and disable ActiveX in untrusted zones.
  • Remove or unregister Msmask32.ocx on systems that do not need Visual Basic 6.0, Visual Studio, or Visual FoxPro development components.
  • Audit hosts for the affected development products and prioritize patching internet-facing or user-workstation systems.

Detection

  • Search for Msmask32.ocx file versions below 6.0.84.18 across endpoints.
  • Monitor for processes loading Msmask32.ocx, especially browser or Office processes, and for unexpected child processes spawned from them.
  • Check registry for the MaskedEdit control kill-bit setting and alert on its removal or absence where policy requires it.
  • Review web proxy and IDS logs for known exploit URLs or payloads associated with the MaskedEdit control.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-3704 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed8.8CVE-2012-0158Microsoft MSCOMCTL.OCX ActiveX controls remote code executionThe ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory…KEVEPSS 100%analysed10.0CVE-2007-0065Microsoft office code injection vulnerabilityHeap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Of…EPSS 43%10.0CVE-2007-1512Microsoft visual studio .net vulnerabilityStack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP…EPSS 11%10.0CVE-2006-4732Microsoft visual basic vulnerabilityUnspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event proce…EPSS 6.8%10.0CVE-2003-0347Microsoft VBA SDK VBE DLL heap buffer overflow via long ID parameterVBE.DLL and VBE6.DLL in the Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 contain a heap-based buffer overflow triggered by a doc…EPSS 55%analysed9.3CVE-2009-2500Microsoft windows 2003 server vulnerabilityInteger overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…EPSS 24%9.3CVE-2009-2501Microsoft windows 2003 server memory buffer overflow vulnerabilityHeap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Offic…EPSS 27%

Source: NIST National Vulnerability Database (record CVE-2008-3704), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.