Main > Security & Privacy > Encrypting >

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0

Sponsored Links

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size:
Platform: Windows Server 2003, Windows XP, Windows 2000
License: update/patch
Price:
Downloads: 12
Date added: 2004-01-12
Publisher: Microsoft. Corp.

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 description

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 is an advanced program which satisfies you with a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and returning data to a client.

When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. Because of a vulnerability in a specific MDAC component, an attacker could respond to this request with a specially-crafted packet that could cause a buffer overflow.

An attacker who successfully exploited this vulnerability could gain the same level of privileges over the system as the program that initiated the broadcast request. The actions an attacker could carry out would be dependent on the permissions under which the program using MDAC ran. If the program ran with limited privileges, an attacker would be limited accordingly; however, if the program ran under the local system context, the attacker would have the same level of permissions.

Since the original version of MDAC on your system may have changed from updates available on the Microsoft Web site, recommend using the following tool to determine the version of MDAC you have on your system: Microsoft Knowledge Base article 301202 "HOW TO: Check for MDAC Version" discusses this tool and explains how to use it. Also, Microsoft Knowledge Base article 231943 discusses the release history of the different versions of MDAC.

Mitigating factors:

  1. For an attack to be successful an attacker would have to simulate a SQL server that is on the same IP subnet as the target system.
  2. When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. A target system must initiate such a broadcast request to be vulnerable to an attack. An attacker would have no way of launching this first step but would have to wait for anyone to enumerate computers that are running SQL Server on the same subnet. Also, a system is not vulnerable by having these SQL management tools installed.
  3. Code executed on the client system would only run under the privileges of the client program that made the broadcast request.

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 Screenshot

Advertisements

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 Keywords

Bookmark Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0

Hyperlink code:
Link for forum:

Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 Copyright

WareSeeker periodically updates pricing and software information of Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Buffer Overrun in MDAC Function Could Allow Code Execution (832483) 1.0 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Microsoft Data Access Components (MDAC) is a collection of components that provides the underlying functionality for a number of database operations, such as connecting to remote databases and Free Download
Find , decode and display the original Product Key Code used when windows / office was installed on your computer Free Download
Protect your files ownership rights while editing, sharing or selling on the net Free Download
Microsoft has released a patch that eliminates a security vulnerability in the Microsoft® Clip Art Gallery. The vulnerability could allow a malicious party to cause hostile code to execute on the com Free Download
Matrix code on Desktop is a new active desktop theme Free Download
FileMaker funciton debugger Free Download
Be Owner Of Your Files Wherever They Go. Free Download
Object-Oriented JNI for .NET (low-level), Library for .NET Framework v.2.0. Supports Standard JNI interface for developing code in C#, MCpp, VB, J#. Free Download