Microsoft Data Access Components Buffer Overflow Vulnerability

BID:5372

Info

Microsoft Data Access Components Buffer Overflow Vulnerability

Bugtraq ID: 5372
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Jul 31 2002 12:00AM
Updated: Jul 31 2002 12:00AM
Credit: Credit is given to David Litchfield of Next Generation Security Software Ltd.
Vulnerable: Microsoft Data Access Components (MDAC) 2.1.1 .3711.11 (GA)
+ Microsoft Internet Explorer 5.0 for Windows NT 4
+ Microsoft Internet Explorer 5.0 for Windows NT 4
+ Microsoft Internet Explorer 5.0 for Windows NT 4
+ Microsoft Internet Explorer 5.0 for Windows 98
+ Microsoft Internet Explorer 5.0 for Windows 98
+ Microsoft Internet Explorer 5.0 for Windows 98
+ Microsoft Office 2000
+ Microsoft Office 2000
+ Microsoft Office 2000
Microsoft Data Access Components (MDAC) 2.7 RTM Refresh
Microsoft Data Access Components (MDAC) 2.7
+ Microsoft Visual Studio .NET Academic Edition 0
+ Microsoft Visual Studio .NET Academic Edition 0
+ Microsoft Visual Studio .NET Academic Edition 0
+ Microsoft Visual Studio .NET Enterprise Architect Edition
+ Microsoft Visual Studio .NET Enterprise Architect Edition
+ Microsoft Visual Studio .NET Enterprise Architect Edition
+ Microsoft Visual Studio .NET Enterprise Developer Edition
+ Microsoft Visual Studio .NET Enterprise Developer Edition
+ Microsoft Visual Studio .NET Enterprise Developer Edition
+ Microsoft Visual Studio .NET Professional Edition
+ Microsoft Visual Studio .NET Professional Edition
+ Microsoft Visual Studio .NET Professional Edition
+ Microsoft Visual Studio .NET Trial Edition 0
+ Microsoft Visual Studio .NET Trial Edition 0
+ Microsoft Visual Studio .NET Trial Edition 0
+ Microsoft Windows XP 0
+ Microsoft Windows XP 0
+ Microsoft Windows XP 64-bit Edition
+ Microsoft Windows XP 64-bit Edition
+ Microsoft Windows XP 64-bit Edition
+ Microsoft Windows XP Home
+ Microsoft Windows XP Home
+ Microsoft Windows XP Home
+ Microsoft Windows XP Professional
+ Microsoft Windows XP Professional
+ Microsoft Windows XP Professional
Microsoft Data Access Components (MDAC) 2.6 SP2 Refresh
Microsoft Data Access Components (MDAC) 2.6 SP2
Microsoft Data Access Components (MDAC) 2.6 SP1
Microsoft Data Access Components (MDAC) 2.6 RTM
Microsoft Data Access Components (MDAC) 2.6
+ Microsoft SQL Server 2000 SP2
+ Microsoft SQL Server 2000 SP2
+ Microsoft SQL Server 2000 SP2
+ Microsoft SQL Server 2000 SP1
+ Microsoft SQL Server 2000 SP1
+ Microsoft SQL Server 2000 SP1
+ Microsoft SQL Server 2000
+ Microsoft SQL Server 2000
+ Microsoft SQL Server 2000
+ Microsoft SQL Server 2000 Desktop Engine
+ Microsoft SQL Server 2000 Desktop Engine
+ Microsoft SQL Server 2000 Desktop Engine
Microsoft Data Access Components (MDAC) 2.5 SP3
Microsoft Data Access Components (MDAC) 2.5 SP2
Microsoft Data Access Components (MDAC) 2.5 SP1
Microsoft Data Access Components (MDAC) 2.5 RTM
Microsoft Data Access Components (MDAC) 2.5
+ Microsoft Office 2000 SP2
+ Microsoft Office 2000 SP2
+ Microsoft Office 2000 SP2
+ Microsoft Office 2000 SP1
+ Microsoft Office 2000 SP1
+ Microsoft Office 2000 SP1
+ Microsoft SQL Server 7.0 SP3 alpha
+ Microsoft SQL Server 7.0 SP3 alpha
+ Microsoft SQL Server 7.0 SP3 alpha
+ Microsoft SQL Server 7.0 SP3
+ Microsoft SQL Server 7.0 SP3
+ Microsoft SQL Server 7.0 SP3
+ Microsoft SQL Server 7.0 SP2 alpha
+ Microsoft SQL Server 7.0 SP2 alpha
+ Microsoft SQL Server 7.0 SP2 alpha
+ Microsoft SQL Server 7.0 SP2
+ Microsoft SQL Server 7.0 SP2
+ Microsoft SQL Server 7.0 SP2
+ Microsoft Windows 2000 Advanced Server SP2
+ Microsoft Windows 2000 Advanced Server SP2
+ Microsoft Windows 2000 Advanced Server SP2
+ Microsoft Windows 2000 Advanced Server SP1
+ Microsoft Windows 2000 Advanced Server SP1
+ Microsoft Windows 2000 Advanced Server SP1
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000 Advanced Server
+ Microsoft Windows 2000 Datacenter Server SP2
+ Microsoft Windows 2000 Datacenter Server SP2
+ Microsoft Windows 2000 Datacenter Server SP2
+ Microsoft Windows 2000 Datacenter Server SP1
+ Microsoft Windows 2000 Datacenter Server SP1
+ Microsoft Windows 2000 Datacenter Server SP1
+ Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000 Datacenter Server
+ Microsoft Windows 2000 Professional SP2
+ Microsoft Windows 2000 Professional SP2
+ Microsoft Windows 2000 Professional SP2
+ Microsoft Windows 2000 Professional SP1
+ Microsoft Windows 2000 Professional SP1
+ Microsoft Windows 2000 Professional SP1
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000 Professional
+ Microsoft Windows 2000 Server SP2
+ Microsoft Windows 2000 Server SP2
+ Microsoft Windows 2000 Server SP2
+ Microsoft Windows 2000 Server SP1
+ Microsoft Windows 2000 Server SP1
+ Microsoft Windows 2000 Server SP1
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000 Server
+ Microsoft Windows 2000 Server Japanese Edition
+ Microsoft Windows 2000 Server Japanese Edition
+ Microsoft Windows 2000 Server Japanese Edition
+ Microsoft Windows 2000 Terminal Services SP2
+ Microsoft Windows 2000 Terminal Services SP2
+ Microsoft Windows 2000 Terminal Services SP2
+ Microsoft Windows 2000 Terminal Services SP1
+ Microsoft Windows 2000 Terminal Services SP1
+ Microsoft Windows 2000 Terminal Services SP1
+ Microsoft Windows 2000 Terminal Services
+ Microsoft Windows 2000 Terminal Services
+ Microsoft Windows 2000 Terminal Services
Microsoft Data Access Components (MDAC) 2.1.2.4202.3 (GA) cl
Microsoft Data Access Components (MDAC) 2.1.2.4202.3 (GA)
Microsoft Data Access Components (MDAC) 2.1 UPGRADE
Microsoft Data Access Components (MDAC) 2.1 CLEAN
Microsoft Data Access Components (MDAC) 2.0
- Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0
Microsoft Data Access Components (MDAC) 1.5
+ Microsoft Windows NT 4.0
+ Microsoft Windows NT 4.0
+ Microsoft Windows NT 4.0
Not Vulnerable:

Discussion

Microsoft Data Access Components Buffer Overflow Vulnerability

Microsoft Data Access Components (MDAC) provide support for accessing databases, including Microsoft SQL Server, and are included with all versions of Microsoft Windows. A vulnerability has been reported in some versions of MDAC.

A buffer overflow vulnerability exists in one of the ODBC functions of MDAC allowing an attacker to run arbitrary code on a victim's machine through a web page containing malicious code. The vulnerability may also be exploited via the T-SQL OpenRowSet command. An attacker able to call this function with an oversized parameter may exploit this issue to crash the SQL Server process, or possibly to execute arbitrary code as the server process. Exploitation may lead to local access, elevated privileges, or access to the database.

Exploit / POC

Microsoft Data Access Components Buffer Overflow Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Microsoft Data Access Components Buffer Overflow Vulnerability

Solution:
Microsoft has released a new fix (Q823718) with BID 8455 that supercedes older fixes released with BID 5372:


Microsoft Data Access Components (MDAC) 2.7

Microsoft Data Access Components (MDAC) 2.6 SP2

Microsoft Data Access Components (MDAC) 2.7 RTM Refresh

Microsoft Data Access Components (MDAC) 2.6 RTM

Microsoft Data Access Components (MDAC) 2.5 SP2

Microsoft Data Access Components (MDAC) 2.6 SP1

Microsoft Data Access Components (MDAC) 2.5 RTM

Microsoft Data Access Components (MDAC) 2.5 SP1

Microsoft Data Access Components (MDAC) 2.6

Microsoft Data Access Components (MDAC) 2.5

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report