PT-2012-3629 · Microsoft · Windows Data Access Components+1
Published
2012-07-10
·
Updated
2024-10-17
·
CVE-2012-1891
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Data Access Components (MDAC) versions 2.8 SP1 through 2.8 SP2
Windows Data Access Components (WDAC) version 6.0
Description
The issue allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory. This is related to a heap-based buffer overflow.
Recommendations
For Microsoft Data Access Components (MDAC) versions 2.8 SP1 and 2.8 SP2, update to a version that includes the fix for this issue.
For Windows Data Access Components (WDAC) version 6.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to crafted XML data to minimize the risk of exploitation.
Fix
Buffer Overflow
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Data Access Components
Windows Data Access Components