SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Generic)  >   Microsoft Data Access Components (MDAC) Vendors:   Microsoft
Microsoft Data Access Components 'ADODB.Connection' Execute Function Lets Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1017127
SecurityTracker URL:  http://securitytracker.com/id/1017127
CVE Reference:   CVE-2006-5559   (Links to External Site)
Updated:  Feb 13 2007
Original Entry Date:  Oct 27 2006
Impact:   Denial of service via network, Execution of arbitrary code via network, User access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  Exploit Included:  Yes  
Version(s): MDAC 2.5 SP3, 2.8, 2.8 SP1
Description:   A vulnerability was reported in Microsoft Microsoft Data Access Components. A remote user can cause denial of service conditions and cause arbitrary code to be executed on the target user's system.

A remote user can create specially crafted HTML that, when loaded by the target user, will execute the ADODB.Connection.Execute function and cause the target user's browser to crash or execute arbitrary code with the privileges of the target user.

A demonstration exploit is available at:

http://www.milw0rm.com/exploits/2629

YAG KOHHA reported this vulnerability.

Impact:   A remote user can create HTML that, when loaded by the target user, will cause the target user's browser to crash or potentially execute arbitrary code.
Solution:   On February 13, 2007, the vendor issued the following fixes:

Microsoft Data Access Components 2.5 Service Pack 3 on Microsoft Windows 2000 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=EF163E3E-DD3B-4429-98A4-720DA2C96464

Microsoft Data Access Components 2.8 Service Pack 1 on Microsoft Windows XP Service Pack 2:

http://www.microsoft.com/downloads/details.aspx?FamilyId=6B0CDB65-AEF4-489F-B917-812D9F7687BD

Microsoft Data Access Components 2.8 on Microsoft Windows Server 2003:

http://www.microsoft.com/downloads/details.aspx?FamilyId=34D24335-4EC0-49E7-9E3F-787F89DD7B1D

Microsoft Data Access Components 2.8 on Microsoft Windows Server 2003 for Itanium-based Systems:

http://www.microsoft.com/downloads/details.aspx?FamilyId=58322D1B-A1A8-4BA6-BA1B-6649013CC324

Microsoft Data Access Components 2.7 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=591B0967-C8AB-4B85-A9AF-C01E8D8E3ADC

Microsoft Data Access Components 2.8 when installed on Microsoft Windows 2000 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=BC864245-175A-4B55-AB4A-FB5D0E03DCFC

Microsoft Data Access Components 2.8 Service Pack 1 when installed on Microsoft Windows 2000 Service Pack 4:

http://www.microsoft.com/downloads/details.aspx?FamilyId=341859BF-8DAA-419B-88CD-E5E8EB4A5BAD

A restart is not required.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/bulletin/ms07-009.mspx

Vendor URL:  www.microsoft.com/technet/security/bulletin/ms07-009.mspx (Links to External Site)
Cause:   Boundary error, State error
Underlying OS:   Windows (Any)

Message History:   None.


 Source Message Contents

Date:  Thu, 26 Oct 2006 20:48:51 -0400
Subject:  Internet Explorer 'ADODB.Connection' object 'Execute' Function Vulnerability POC


http://www.milw0rm.com/exploits/2629
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2014, SecurityGlobal.net LLC