peter bassill · operator
$ cve CVE-2011-0027 JSON

CVE-2011-0027 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 54.4% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS54.37% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2011-01-12
Last modified2026-06-16

Affected (8)

VendorProduct
microsoftdata access components
microsoftwindows 2003 server
microsoftwindows 7
microsoftwindows data access components
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD