KEVIntel
9.3
CVSS
High

CVE-2008-3704

PUBLISHED

Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft...

Not yet in CISA KEV

Exploited in the wild PoC available Remote
Vendor
Microsoft
Product
Visual Studio
Published
Aug 18, 2008
EPSS

Automate This Intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

dotnet metasploit

CVSS Scores

CVSS v2.0 9.3 High

AV:N/AC:M/Au:N/C:C/I:C/A:C

Exploitation Status

Exploited in the wild

Recorded 2008-08-18 19:00:00 UTC · CVE

Proof of concept available

Recorded 2025-04-28 15:02:40 UTC

Known Exploited Vulnerability Sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2008-08-18 19:00 UTC

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

ms08_070_visual_studio_msmask

metasploit · Created Unknown

Metasploit module for CVE-2008-3704

Timeline

  • Detected by Metasploit

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • CVE Published to Public

  • CVE ID Reserved