Overview
A vulnerability in the Microsoft Data Access Components (MDAC) could lead to remote execution of code with the privileges of the current process, or user.
Description
Microsoft Data Access Components (MDAC) is a collection of utilities and routines to process requests between databases and network applications. A buffer overflow vulnerability exists in the Remote Data Services (RDS) component of MDAC. The RDS component provides an intermediary step for a client's request for service from a back-end database which enables the web site to apply business logic to the request. |
Impact
A remote attacker could execute arbitrary code with the privileges of the application that processed the request. |
Solution
Apply a patch from your vendor.
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/security/security_bulletins/ms02-065.asp
- http://www.microsoft.com/technet/security/bulletin/MS02-065.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnmdac/html/technologyfeatures.asp
- http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
Acknowledgements
This vulnerability was reported in an advisory by Foundstone and in MS02-065 by Microsoft.
This document was written by Jason A Rafail.
Other Information
CVE IDs: | CVE-2002-1142 |
CERT Advisory: | CA-2002-33 |
Severity Metric: | 52.58 |
Date Public: | 2002-11-20 |
Date First Published: | 2002-11-20 |
Date Last Updated: | 2002-12-13 19:02 UTC |
Document Revision: | 9 |