PT-2012-3629 · Microsoft · Windows Data Access Components+1

Published

2012-07-10

·

Updated

2024-10-17

·

CVE-2012-1891

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Data Access Components (MDAC) versions 2.8 SP1 through 2.8 SP2 Windows Data Access Components (WDAC) version 6.0
Description The issue allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory. This is related to a heap-based buffer overflow.
Recommendations For Microsoft Data Access Components (MDAC) versions 2.8 SP1 and 2.8 SP2, update to a version that includes the fix for this issue. For Windows Data Access Components (WDAC) version 6.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to crafted XML data to minimize the risk of exploitation.

Fix

Buffer Overflow

Use of Uninitialized Resource

Weakness Enumeration

Related Identifiers

CVE-2012-1891
ZDI-12-158

Affected Products

Data Access Components
Windows Data Access Components