CVE-2011-0027 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 54.4% (pctl 99)
Patch early
A public exploit exists.
Description
Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 54.37% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-01-12 |
| Last modified | 2026-06-16 |
Affected (8)
| Vendor | Product |
|---|---|
| microsoft | data access components |
| microsoft | windows 2003 server |
| microsoft | windows 7 |
| microsoft | windows data access components |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows vista |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Data Access Components - Remote Overflow (MS11-002) | 2011-01-12 |
References
- http://osvdb.org/70444
- http://secunia.com/advisories/42804
- http://support.avaya.com/css/P8/documents/100124846
- http://vreugdenhilresearch.nl/ms11-002-pwn2own-heap-overflow/
- http://www.securityfocus.com/bid/45698
- http://www.securitytracker.com/id?1024947
- http://www.us-cert.gov/cas/techalerts/TA11-011A.html
- http://www.vupen.com/english/advisories/2011/0075
- http://www.zerodayinitiative.com/advisories/ZDI-11-002/
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-002
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12411
- http://osvdb.org/70444
- http://secunia.com/advisories/42804
- http://support.avaya.com/css/P8/documents/100124846
- http://vreugdenhilresearch.nl/ms11-002-pwn2own-heap-overflow/
- http://www.securityfocus.com/bid/45698
- http://www.securitytracker.com/id?1024947
- http://www.us-cert.gov/cas/techalerts/TA11-011A.html
- http://www.vupen.com/english/advisories/2011/0075
- http://www.zerodayinitiative.com/advisories/ZDI-11-002/
→ the Explorer · watch your stack · NVD