PT-2019-2422 · Microsoft · Activex Data Objects+1

Yaniv Frank

·

Published

2019-06-11

·

Updated

2025-05-20

·

CVE-2019-0888

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows ActiveX Data Objects (ADO) (affected versions not specified)
Description A remote code execution issue exists due to the way ActiveX Data Objects (ADO) handle objects in memory. This allows remote attackers to execute arbitrary code and affect the system. The issue is related to a Use-After-Free error in Windows ActiveX Data Objects (ADO).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2019-02200
CVE-2019-0888

Affected Products

Activex Data Objects
Windows