Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
BID:20704
Info
Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
| Bugtraq ID: | 20704 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5559 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2006 12:00AM |
| Updated: | Mar 26 2007 07:33PM |
| Credit: | YAG KOHHA is credited with discovering this issue. |
| Vulnerable: |
Nortel Networks Symposium TAPI Service Provider Nortel Networks Symposium Network Control Center (NCC) Nortel Networks Symposium Agent Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center - TAPI Server 0 Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager 8.0 Nortel Networks Centrex IP Client Manager 7.0 Nortel Networks Centrex IP Client Manager 2.5 Nortel Networks Centrex IP Client Manager 9.0 Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Microsoft Data Access Components (MDAC) 2.8 SP1 Microsoft Data Access Components (MDAC) 2.8 SP1 Microsoft Data Access Components (MDAC) 2.8 Microsoft Data Access Components (MDAC) 2.8 Microsoft Data Access Components (MDAC) 2.5 SP3 HP Storage Management Appliance 2.1 Avaya Web Messenger 0 Avaya VPNmanagerTM Console 0 Avaya Visual Vector Client 0 Avaya Visual Messenger TM 0 Avaya Unified Messenger (r) 0 Avaya Unified Communication Center Avaya S8100 Media Servers R9 Avaya S8100 Media Servers R8 Avaya S8100 Media Servers R7 Avaya S8100 Media Servers R6 Avaya S8100 Media Servers R12 Avaya S8100 Media Servers R11 Avaya S8100 Media Servers R10 Avaya S8100 Media Servers 0 Avaya Outbound Contact Management 0 Avaya Operational Analyst 0 Avaya OctelDesignerTM 0 Avaya OctelAccess(r) Server 0 Avaya Network Reporting 0 Avaya Modular Messaging (MAS) Avaya Messaging Application Server 0 Avaya IP Softphone 0 Avaya IP Agent 0 Avaya Interaction Center 0 Avaya Integrated Management Avaya Enterprise Management 0 Avaya CVLAN Avaya Contact Center Express 0 Avaya Computer Telephony 0 Avaya CMS Supervisor 0 Avaya Basic Call Management System Reporting Desktop server Avaya Basic Call Management System Reporting Desktop 0 Avaya Agent Access 0 |
| Not Vulnerable: |
Microsoft Data Access Components (MDAC) 2.8 SP2 |
Discussion
Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption condition when processing a specific method from the 'ADODB.Connection.2.7' instantiated ActiveX Object.
Successful exploits may allow attackers to crash the application, denying further service to users. This issue may also be exploited to execute arbitrary machine-code, but this has not been confirmed.
This issue does not affect Microsoft Data Access Components 2.8 on Windows Vista.
Microsoft Internet Explorer is prone to a memory-corruption condition when processing a specific method from the 'ADODB.Connection.2.7' instantiated ActiveX Object.
Successful exploits may allow attackers to crash the application, denying further service to users. This issue may also be exploited to execute arbitrary machine-code, but this has not been confirmed.
This issue does not affect Microsoft Data Access Components 2.8 on Windows Vista.
Exploit / POC
Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
The following exploit code examples are available:
The following exploit code examples are available:
Solution / Fix
Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
Solution:
The vendor has released fixes and an advisory to address this issue; please see the references for more information.
Microsoft Data Access Components (MDAC) 2.8
Microsoft Data Access Components (MDAC) 2.8 SP1
Microsoft Data Access Components (MDAC) 2.5 SP3
Solution:
The vendor has released fixes and an advisory to address this issue; please see the references for more information.
Microsoft Data Access Components (MDAC) 2.8
-
Microsoft Security Update for Windows Server 2003 (KB927779)
http://www.microsoft.com/downloads/details.aspx?FamilyId=34D24335-4EC0 -49E7-9E3F-787F89DD7B1D -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB927779)
http://www.microsoft.com/downloads/details.aspx?FamilyId=58322D1B-A1A8 -4BA6-BA1B-6649013CC324
Microsoft Data Access Components (MDAC) 2.8 SP1
-
Microsoft Security Update for Windows XP (KB927779)
http://www.microsoft.com/downloads/details.aspx?FamilyId=6B0CDB65-AEF4 -489F-B917-812D9F7687BD
Microsoft Data Access Components (MDAC) 2.5 SP3
-
Microsoft Security Update for Microsoft Data Access Components 2.5 Service Pack 3 (KB927779)
http://www.microsoft.com/downloads/details.aspx?FamilyId=EF163E3E-DD3B -4429-98A4-720DA2C96464
References
Microsoft Internet Explorer ADODB.Connection Execute Memory Corruption Vulnerability
References:
References:
- 2007007744 - NORTEL RESPONSE TO MICROSOFT SECURITY BULLETIN MS07-009 (Nortel)
- ADODB.Connection POC Published. (Microsoft)
- MSIE Product Homepage (Microsoft)
- Vulnerability Note VU#589272 (US-CERT)
- HPSBST02194 SSRT071306 rev.1 - Storage Management Appliance (SMA), Microsoft Pat (HP)
- ASA-2007-082: MS07-009 Vulnerability in Microsoft Data Access Components Could A (Avaya)
- CENTREX IP CLIENT MANAGER (CICM) RESPONSE TO MICROSOFT FEBRUARY SECURITY BULLETI (Nortel Networks)