← Vulnerability feed

Vulnerability record · CVE-2008-4255 · published 10 December 2008

CVE-2008-4255: Windows Common ActiveX control heap overflow via crafted AVI stream

Microsoft · Office Frontpage

The mscomct2.ocx ActiveX control (Windows Common / Microsoft Animation control) contains a heap-based buffer overflow when parsing an AVI file with a crafted stream length, causing an allocation error and memory corruption. The control ships with Visual Basic 6.0, Visual Studio .NET 2002/2003, Visual FoxPro 8.0/9.0, and Office Project 2003/2007, so the flaw affects a broad set of Microsoft development and project tools.

9.3 CVSS 2.0 High EPSS 54% · top 1.0% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
22References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2003 SP3 and 2007 Gold and SP1 allows remote attackers to execute arbitrary code via an AVI file with a crafted stream length, which triggers an "allocation error" and memory corruption, aka "Windows Common AVI Parsing Overflow Vulnerability."

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote code execution with complete impact and a very high EPSS score, though exploitation requires a medium-complexity condition and the flaw is long patched.

What it is

The mscomct2.ocx ActiveX control (Windows Common / Microsoft Animation control) contains a heap-based buffer overflow when parsing an AVI file with a crafted stream length, causing an allocation error and memory corruption. The control ships with Visual Basic 6.0, Visual Studio .NET 2002/2003, Visual FoxPro 8.0/9.0, and Office Project 2003/2007, so the flaw affects a broad set of Microsoft development and project tools.

Impact

A remote attacker can execute arbitrary code in the context of the user or application that loads the control, giving full control of confidentiality, integrity and availability per the CVSS vector.

Attack surface

Reached over the network (AV:N) by delivering a malicious AVI to a host where the ActiveX control is instantiated, typically through a web page or document. No authentication is required (Au:N), but the CVSS vector rates attack complexity as medium (AC:M), implying some condition such as user interaction or a specific rendering path must be met.

Exploitation

Not listed in CISA KEV, but EPSS is 0.53703 (99th percentile), indicating high predicted exploitation activity, and a public exploit reference is present in the record. No ransomware group is documented as using it.

What to do

  • Apply Microsoft security bulletin MS08-070, which addresses this vulnerability, and prioritize systems running Visual Basic 6.0, Visual Studio .NET 2002/2003, Visual FoxPro 8.0/9.0, and Office Project 2003/2007.
  • Set the kill bit for the vulnerable mscomct2.ocx control (CLSID) in environments where it is not required.
  • Restrict or block the control from running in Internet Explorer and other ActiveX hosts via zone and ActiveX policy settings.
  • Prevent untrusted AVI files from reaching applications that instantiate the control, and block AVI attachments at email and web gateways where feasible.
  • Where the control cannot be removed, isolate affected development and Office Project workstations from untrusted network content.

Detection

  • Monitor for mscomct2.ocx being loaded by browser, Office, or development tool processes, especially when followed by unexpected child processes.
  • Alert on process creation from Office, Visual Studio, or Visual FoxPro processes spawning command shells or scripting hosts.
  • Hunt for AVI files with anomalous stream-length fields delivered via email or web download to hosts with the affected products installed.
  • Check endpoint inventories for the affected Microsoft products and confirm the MS08-070 update or kill-bit registry setting is applied.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-4255 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1856Microsoft Office MSCOMCTL.OCX TabStrip ActiveX Control Remote Code ExecutionThe TabStrip ActiveX control in MSCOMCTL.OCX fails to properly handle system state, allowing a crafted document or web page to corrupt memory and exe…KEVEPSS 72%analysed8.8CVE-2012-0158Microsoft MSCOMCTL.OCX ActiveX controls remote code executionThe ListView, ListView2, TreeView and TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls fail to handle crafted input, allowing memory…KEVEPSS 100%analysed8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed10.0CVE-2007-0065Microsoft office code injection vulnerabilityHeap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Of…EPSS 43%10.0CVE-2007-1512Microsoft visual studio .net vulnerabilityStack-based buffer overflow in the AfxOleSetEditMenu function in the MFC component in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 Gold and SP…EPSS 11%10.0CVE-2006-4732Microsoft visual basic vulnerabilityUnspecified vulnerability in Microsoft Visual Basic (VB) 6 has an unknown impact ("overflow") via a project that contains a certain Click event proce…EPSS 6.8%10.0CVE-2003-0347Microsoft VBA SDK VBE DLL heap buffer overflow via long ID parameterVBE.DLL and VBE6.DLL in the Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 contain a heap-based buffer overflow triggered by a doc…EPSS 55%analysed9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2008-4255), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.