Описание
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
Ссылки
- Patch
- Vendor Advisory
- ExploitPatchVendor Advisory
- PatchUS Government Resource
- ExploitPatch
- US Government Resource
- Vendor Advisory
- Patch
- Vendor Advisory
- ExploitPatchVendor Advisory
- PatchUS Government Resource
- ExploitPatch
- US Government Resource
Уязвимые конфигурации
Одновременно
Одновременно
Одновременно
Одно из
Одновременно
Одновременно
Одновременно
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
EPSS
9.3 Critical
CVSS2