Vulnerability record · CVE-2008-4255 · published 10 December 2008
CVE-2008-4255: Windows Common ActiveX control heap overflow via crafted AVI stream
Microsoft · Office Frontpage
The mscomct2.ocx ActiveX control (Windows Common / Microsoft Animation control) contains a heap-based buffer overflow when parsing an AVI file with a crafted stream length, causing an allocation error and memory corruption. The control ships with Visual Basic 6.0, Visual Studio .NET 2002/2003, Visual FoxPro 8.0/9.0, and Office Project 2003/2007, so the flaw affects a broad set of Microsoft development and project tools.
Description
Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a very high EPSS score, though exploitation requires a medium-complexity condition and the flaw is long patched.
What it is
The mscomct2.ocx ActiveX control (Windows Common / Microsoft Animation control) contains a heap-based buffer overflow when parsing an AVI file with a crafted stream length, causing an allocation error and memory corruption. The control ships with Visual Basic 6.0, Visual Studio .NET 2002/2003, Visual FoxPro 8.0/9.0, and Office Project 2003/2007, so the flaw affects a broad set of Microsoft development and project tools.
Impact
A remote attacker can execute arbitrary code in the context of the user or application that loads the control, giving full control of confidentiality, integrity and availability per the CVSS vector.
Attack surface
Reached over the network (AV:N) by delivering a malicious AVI to a host where the ActiveX control is instantiated, typically through a web page or document. No authentication is required (Au:N), but the CVSS vector rates attack complexity as medium (AC:M), implying some condition such as user interaction or a specific rendering path must be met.
Exploitation
Not listed in CISA KEV, but EPSS is 0.53703 (99th percentile), indicating high predicted exploitation activity, and a public exploit reference is present in the record. No ransomware group is documented as using it.
What to do
- Apply Microsoft security bulletin MS08-070, which addresses this vulnerability, and prioritize systems running Visual Basic 6.0, Visual Studio .NET 2002/2003, Visual FoxPro 8.0/9.0, and Office Project 2003/2007.
- Set the kill bit for the vulnerable mscomct2.ocx control (CLSID) in environments where it is not required.
- Restrict or block the control from running in Internet Explorer and other ActiveX hosts via zone and ActiveX policy settings.
- Prevent untrusted AVI files from reaching applications that instantiate the control, and block AVI attachments at email and web gateways where feasible.
- Where the control cannot be removed, isolate affected development and Office Project workstations from untrusted network content.
Detection
- Monitor for mscomct2.ocx being loaded by browser, Office, or development tool processes, especially when followed by unexpected child processes.
- Alert on process creation from Office, Visual Studio, or Visual FoxPro processes spawning command shells or scripting hosts.
- Hunt for AVI files with anomalous stream-length fields delivered via email or web download to hosts with the affected products installed.
- Check endpoint inventories for the affected Microsoft products and confirm the MS08-070 update or kill-bit registry setting is applied.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4255 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.