Microsoft Data Access Components 'ADODB.Connection' Execute Function Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1017127 |
|
SecurityTracker URL: http://securitytracker.com/id/1017127
|
|
CVE Reference:
CVE-2006-5559
(Links to External Site)
|
Updated: Feb 13 2007
|
Original Entry Date: Oct 27 2006
|
Impact:
Denial of service via network, Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes Exploit Included: Yes
|
Version(s): MDAC 2.5 SP3, 2.8, 2.8 SP1
|
Description:
A vulnerability was reported in Microsoft Microsoft Data Access Components. A remote user can cause denial of service conditions and cause arbitrary code to be executed on the target user's system.
A remote user can create specially crafted HTML that, when loaded by the target user, will execute the ADODB.Connection.Execute function and cause the target user's browser to crash or execute arbitrary code with the privileges of the target user.
A demonstration exploit is available at:
http://www.milw0rm.com/exploits/2629
YAG KOHHA reported this vulnerability.
|
Impact:
A remote user can create HTML that, when loaded by the target user, will cause the target user's browser to crash or potentially execute arbitrary code.
|
Solution:
On February 13, 2007, the vendor issued the following fixes:
Microsoft Data Access Components 2.5 Service Pack 3 on Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=EF163E3E-DD3B-4429-98A4-720DA2C96464
Microsoft Data Access Components 2.8 Service Pack 1 on Microsoft Windows XP Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=6B0CDB65-AEF4-489F-B917-812D9F7687BD
Microsoft Data Access Components 2.8 on Microsoft Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=34D24335-4EC0-49E7-9E3F-787F89DD7B1D
Microsoft Data Access Components 2.8 on Microsoft Windows Server 2003 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?FamilyId=58322D1B-A1A8-4BA6-BA1B-6649013CC324
Microsoft Data Access Components 2.7 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=591B0967-C8AB-4B85-A9AF-C01E8D8E3ADC
Microsoft Data Access Components 2.8 when installed on Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=BC864245-175A-4B55-AB4A-FB5D0E03DCFC
Microsoft Data Access Components 2.8 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=341859BF-8DAA-419B-88CD-E5E8EB4A5BAD
A restart is not required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms07-009.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms07-009.mspx (Links to External Site)
|
Cause:
Boundary error, State error
|
Underlying OS:
Windows (Any)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Thu, 26 Oct 2006 20:48:51 -0400
Subject: Internet Explorer 'ADODB.Connection' object 'Execute' Function Vulnerability POC
|
http://www.milw0rm.com/exploits/2629
|
|