Overview
Microsoft Data Access Components (MDAC) contains a buffer overflow vulnerability that could allow a remote attacker to execute arbitrary code or cause a denial of service.
Description
| From Microsoft Security Bulletin MS04-003: Microsoft Data Access Components (MDAC) is a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and returning data to a client. | 
Impact
| A remote attacker could execute arbitrary code with the privileges of the process using MDAC. The attacker could also cause a denial of service. | 
Solution
| Apply patch | 
| 
 | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
- http://www.microsoft.com/technet/security/bulletin/ms04-003.asp
- http://support.microsoft.com/default.aspx?kbid=301202
- http://support.microsoft.com/default.aspx?kbid=231943
- http://support.microsoft.com/default.aspx?kbid=813878
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnmdac/html/technologyfeatures.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnmdac/html/datechartoverview.asp
- http://www.secunia.com/advisories/10616/
- http://www.securityfocus.com/bid/9407
Acknowledgements
Information used in this document came from Microsoft Security Bulletin MS04-003.
This document was written by Art Manion.
Other Information
| CVE IDs: | CVE-2003-0903 | 
| Severity Metric: | 10.60 | 
| Date Public: | 2004-01-13 | 
| Date First Published: | 2004-01-19 | 
| Date Last Updated: | 2004-01-19 14:58 UTC | 
| Document Revision: | 28 |