PT-2012-3629 · Microsoft · Windows Data Access Components+1

CVE-2012-1891

·

Publicado

2012-07-10

·

Atualizado

2024-10-17

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Data Access Components (MDAC) versions 2.8 SP1 through 2.8 SP2 Windows Data Access Components (WDAC) version 6.0
Description The issue allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory. This is related to a heap-based buffer overflow.
Recommendations For Microsoft Data Access Components (MDAC) versions 2.8 SP1 and 2.8 SP2, update to a version that includes the fix for this issue. For Windows Data Access Components (WDAC) version 6.0, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to crafted XML data to minimize the risk of exploitation.

Correção

Buffer Overflow

Use of Uninitialized Resource

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1891
ZDI-12-158

Produtos afetados

Data Access Components
Windows Data Access Components