CVE-2011-0027
Summary
| CVE | CVE-2011-0027 |
|---|---|
| State | PUBLISHED |
| Assigner | microsoft |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-12 01:00:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Data Access Components | 2.8 | sp1 | All | All |
| Application | Microsoft | Data Access Components | 2.8 | sp2 | All | All |
| Operating System | Microsoft | Windows 2003 Server | All | sp2 | All | All |
| Operating System | Microsoft | Windows 7 | - | All | All | All |
| Application | Microsoft | Windows Data Access Components | 6.0 | All | All | All |
| Operating System | Microsoft | Windows Server 2003 | All | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | All | All | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x32 | All |
| Operating System | Microsoft | Windows Server 2008 | All | sp2 | x64 | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | All | itanium | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | All | x64 | All |
| Operating System | Microsoft | Windows Vista | All | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | All | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | All | All | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | x64 | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Microsoft Data Access Components (MDAC) Memory Corruption Errors in Processing DSN Data and ADO Records Let Remote Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Vreugdenhil Research » Blog Archive » MS11-002 Pwn2Own heap overflow | af854a3a-2127-422b-91ae-364da2661108 | vreugdenhilresearch.nl | |
| Microsoft Data Access Components Two Vulnerabilities - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Microsoft Data Access Components ActiveX Data Objects Memory Corruption Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Microsoft Security Bulletin MS11-002 - Critical | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | |
| osvdb.org/70444 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| US-CERT Technical Cyber Security Alert TA11-011A -- Microsoft Updates for Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| ASA-2011-006 (2451910) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.