Microsoft JET Text I-ISAM Vulnerability

BID:595

Info

Microsoft JET Text I-ISAM Vulnerability

Bugtraq ID: 595
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Aug 20 1999 12:00AM
Updated: Aug 20 1999 12:00AM
Credit: Reported by Microsoft in Security Bulletin MS99-030, released August 20, 1999.
Vulnerable: Microsoft JET 4.0
+ Microsoft Access 2000
+ Microsoft Access 2000
Microsoft JET 3.51
+ Microsoft Excel 95
+ Microsoft Excel 95
+ Microsoft Excel 97
+ Microsoft Excel 97
Microsoft JET 3.5
+ Microsoft Access 95
+ Microsoft Access 95
+ Microsoft Access 97
+ Microsoft Access 97
Not Vulnerable: Microsoft JET 4.0 SP1
Microsoft JET 3.51 SP3

Discussion

Microsoft JET Text I-ISAM Vulnerability

Microsoft's JET database engine includes functionality referred to as Text I-ISAM. This allows the JET driver to write to a text file for another application to read later. This was implemented to allow data sharing between JET applications and other applications that don't support Dynamic Data Exchange.

A vulnerability exists in Text I-ISAM functionality that can result in any text file being written to, including system files. To exploit this issue, a database query could be created that adds destructive commands to a startup file or script.

Exploit / POC

Microsoft JET Text I-ISAM Vulnerability

Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Microsoft JET Text I-ISAM Vulnerability

Solution:
Microsoft has released a patch for this issue. To quote Microsoft advisory MS99-030:

- http://officeupdate.microsoft.com/articles/mdac_typ.htm

NOTES:
- The above web site provides separate pages for Office97 and
Office2000. This is done in order to provide specific information
about the vulnerabilities affecting the products. The patch for
Office97 and Office2000 (and indeed for all affected products) is
exactly the same, and both pages link to exactly the same patch.
The patch will determine what version(s) of Jet are present on
the machine and apply all of the needed corrections.
- The patch is suitable for use by all language packs.
- The patch applies to Jet 3.5 and all subsequent versions. Older
versions of Jet are no longer supported, and we recommend that
affected customers upgrade to a supported version.
- The patch is suitable for widespread deployment via Microsoft(r)
Systems Management Server(r). Users who wish to manually apply
patches for specific versions of Jet should consult the FAQ for
information on how to do this.

An additional patch made available by Microsoft, exists at the following location:
http://office.microsoft.com/assistance/9798/mdac_typ.aspx

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report