CVE-2012-1891
9.8
CRITICAL · CVSS 3.1 · EPSS 29.4% (pctl 98)
Patch early
EPSS 29.4% — above the 10% action threshold.
Description
Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 29.41% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2012-07-10 |
| Last modified | 2026-06-16 |
Affected (7)
| Vendor | Product |
|---|---|
| microsoft | data access components |
| microsoft | windows 7 |
| microsoft | windows data access components |
| microsoft | windows server 2003 |
| microsoft | windows server 2008 |
| microsoft | windows vista |
| microsoft | windows xp |
References
- http://www.us-cert.gov/cas/techalerts/TA12-192A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14783
- http://www.us-cert.gov/cas/techalerts/TA12-192A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14783
→ the Explorer · watch your stack · NVD