Buffer-Overrun Vulnerability in MDAC

Foundstone discovered that a Microsoft Data Access Components (MDAC) vulnerability might let a potential attacker execute arbitrary code on the vulnerable system.

ITPro Today

December 4, 2002

1 Min Read
ITPro Today logo

Foundstone discovered that a Microsoft Data Access Components (MDAC) vulnerability might let a potential attacker execute arbitrary code on the vulnerable system. The vulnerability stems from an unchecked buffer in the Remote Data Services (RDS) Data Stub. By sending a specially malformed HTTP request to the Data Stub, a potential attacker can cause targeted data to overrun onto the heap. Microsoft has released Security Bulletin MS02-065 (Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution) to address this vulnerability and recommends that affected users immediately apply the appropriate patch that the bulletin mentions.

http://www.secadministrator.com/articles/index.cfm?articleid=27357 .

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like