← Vulnerability feed

Vulnerability record · CVE-2008-4253 · published 10 December 2008

CVE-2008-4253: Microsoft office frontpage vulnerability

Microsoft · Office Frontpage

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."

8.5 CVSS 2.0 High EPSS 21% · top 2.5% CWE-399 · CWE-399
8.5CVSS 2.0 base score
21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project 2003 SP3 does not properly handle errors during access to incorrectly initialized objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to corruption of the "system state," aka "FlexGrid Control Memory Corruption Vulnerability."

AV:N/AC:M/Au:S/C:C/I:C/A:C

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed8.8CVE-2012-0158Microsoft MSCOMCTL.OCX ActiveX controls remote code executionThe ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory…KEVEPSS 100%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed10.0CVE-2007-0065Microsoft office code injection vulnerabilityHeap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Of…EPSS 43%10.0CVE-2007-1512Microsoft visual studio .net vulnerabilityStack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP…EPSS 11%10.0CVE-2006-4732Microsoft visual basic vulnerabilityUnspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event proce…EPSS 6.8%10.0CVE-2003-0347Microsoft VBA SDK VBE DLL heap buffer overflow via long ID parameterVBE.DLL and VBE6.DLL in the Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 contain a heap-based buffer overflow triggered by a doc…EPSS 55%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2008-4253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.