peter bassill · operator
$ cve CVE-2012-1891 JSON

CVE-2012-1891

9.8
CRITICAL · CVSS 3.1 · EPSS 29.4% (pctl 98)

Patch early

EPSS 29.4% — above the 10% action threshold.

Description

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS29.41% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2012-07-10
Last modified2026-06-16

Affected (7)

VendorProduct
microsoftdata access components
microsoftwindows 7
microsoftwindows data access components
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp

References

→ the Explorer  ·  watch your stack  ·  NVD