Buffer Overflow in Microsoft Visual Basic Enterprise Edition 6.0 SP6
CVE-2008-2959

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
2 July 2008

Summary

A buffer overflow exists within the ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6, allowing remote attackers to execute arbitrary code. This vulnerability is triggered by an overly long lpstrLinkPath argument to the fCreateShellLink function, potentially compromising system integrity and exposing sensitive information.

References

EPSS Score

34% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.