PT-2006-6274 · Microsoft · Adodb.Connection+2

Yag Kohha

·

Publicado

2006-10-27

·

Atualizado

2018-10-12

·

CVE-2006-5559

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MDAC versions 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 ADODB.Connection versions 2.7 and 2.8
Description: The issue is related to the Execute method in the ADODB.Connection ActiveX control objects. It does not properly track freed memory when the second argument is a BSTR. This allows remote attackers to cause a denial of service, such as an Internet Explorer crash, and possibly execute arbitrary code via certain strings in the second and third arguments.
Recommendations: For MDAC versions 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1, consider disabling the Execute method in the ADODB.Connection ActiveX control objects until a patch is available. For ADODB.Connection versions 2.7 and 2.8, restrict access to the Execute method to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-5559

Produtos afetados

Adodb.Connection
Internet Explorer
Mdac