PT-2012-3629 · Microsoft · Windows Data Access Components+1
CVE-2012-1891
·
Publicado
2012-07-10
·
Atualizado
2024-10-17
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Data Access Components (MDAC) versions 2.8 SP1 through 2.8 SP2
Windows Data Access Components (WDAC) version 6.0
Description
The issue allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory. This is related to a heap-based buffer overflow.
Recommendations
For Microsoft Data Access Components (MDAC) versions 2.8 SP1 and 2.8 SP2, update to a version that includes the fix for this issue.
For Windows Data Access Components (WDAC) version 6.0, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to crafted XML data to minimize the risk of exploitation.
Correção
Buffer Overflow
Use of Uninitialized Resource
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Data Access Components
Windows Data Access Components