CVE-2006-5559 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 43.6% (pctl 99)
Patch early
A public exploit exists.
Description
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 43.62% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-10-27 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| microsoft | data access components |
| microsoft | windows 2000 |
| microsoft | windows 2003 server |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer - ADODB Execute Denial of Service (PoC) | 2006-10-24 |
References
- http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx
- http://research.eeye.com/html/alerts/zeroday/20061027.html
- http://secunia.com/advisories/22452
- http://securitytracker.com/id?1017127
- http://www.kb.cert.org/vuls/id/589272
- http://www.osvdb.org/31882
- http://www.securityfocus.com/bid/20704
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
- http://www.vupen.com/english/advisories/2007/0578
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29837
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214
- http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx
- http://research.eeye.com/html/alerts/zeroday/20061027.html
- http://secunia.com/advisories/22452
- http://securitytracker.com/id?1017127
- http://www.kb.cert.org/vuls/id/589272
- http://www.osvdb.org/31882
- http://www.securityfocus.com/bid/20704
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
→ the Explorer · watch your stack · NVD