Overview
A vulnerability in the Microsoft Data Access Components (MDAC) could lead to remote execution of code with the privileges of the current process, or user.
Description
| Microsoft Data Access Components (MDAC) is a collection of utilities and routines to process requests between databases and network applications. A buffer overflow vulnerability exists in the Remote Data Services (RDS) component of MDAC. The RDS component provides an intermediary step for a client's request for service from a back-end database which enables the web site to apply business logic to the request.  | 
Impact
| A remote attacker could execute arbitrary code with the privileges of the application that processed the request.  | 
Solution
| Apply a patch from your vendor. 
 | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
- http://www.microsoft.com/security/security_bulletins/ms02-065.asp
- http://www.microsoft.com/technet/security/bulletin/MS02-065.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnmdac/html/technologyfeatures.asp
- http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
Acknowledgements
This vulnerability was reported in an advisory by Foundstone and in MS02-065 by Microsoft.
This document was written by Jason A Rafail.
Other Information
| CVE IDs: | CVE-2002-1142 | 
| CERT Advisory: | CA-2002-33 | 
| Severity Metric: | 52.58 | 
| Date Public: | 2002-11-20 | 
| Date First Published: | 2002-11-20 | 
| Date Last Updated: | 2002-12-13 19:02 UTC | 
| Document Revision: | 9 |