CVE-2002-1142 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 76% (pctl 100)
Patch early
A public exploit exists.
Description
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 76% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2002-11-29 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | data access components |
| microsoft | ie |
| microsoft | internet explorer |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft IIS - MDAC 'msadcs.dll' RDS DataStub Content-Type Overflow (MS02-065) (Metasploit) | 2012-06-08 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.html
- http://www.cert.org/advisories/CA-2002-33.html
- http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
- http://www.kb.cert.org/vuls/id/542081
- http://www.securityfocus.com/bid/6214
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10659
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10669
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A294
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3573
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.html
- http://www.cert.org/advisories/CA-2002-33.html
- http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
- http://www.kb.cert.org/vuls/id/542081
- http://www.securityfocus.com/bid/6214
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10659
- https://exchange.xforce.ibmcloud.com/vulnerabilities/10669
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730
→ the Explorer · watch your stack · NVD