Buffer Overrun in MDAC Function Could Allow Code E 1.0
Buffer Overrun in MDAC Function Could Allow Code E 1.0 Ranking & Summary
Buffer Overrun in MDAC Function Could Allow Code E 1.0 description
An attacker who successfully exploited this vulnerability could gain the same level of privileges over the system as the program that initiated the broadcast request. The actions an attacker could carry out would be dependent on the permissions under which the program using MDAC ran. If the program ran with limited privileges, an attacker would be limited accordingly; however, if the program ran under the local system context, the attacker would have the same level of permissions.
Since the original version of MDAC on your system may have changed from updates available on the Microsoft Web site, we recommend using the following tool to determine the version of MDAC you have on your system: Microsoft Knowledge Base article 301202 "HOW TO: Check for MDAC Version" discusses this tool and explains how to use it. Also, Microsoft Knowledge Base article 231943 discusses the release history of the different versions of MDAC.
Mitigating factors:
- For an attack to be successful an attacker would have to simulate a SQL server that is on the same IP subnet as the target system.
- When a client system on a network tries to see a list of computers that are running SQL Server and that reside on the network, it sends a broadcast request to all the devices that are on the network. A target system must initiate such a broadcast request to be vulnerable to an attack. An attacker would have no way of launching this first step but would have to wait for anyone to enumerate computers that are running SQL Server on the same subnet. Also, a system is not vulnerable by having these SQL management tools installed.
- Code executed on the client system would only run under the privileges of the client program that made the broadcast request.
Buffer Overrun in MDAC Function Could Allow Code E 1.0 Screenshot
Buffer Overrun in MDAC Function Could Allow Code E 1.0 Keywords
Bookmark Buffer Overrun in MDAC Function Could Allow Code E 1.0
Buffer Overrun in MDAC Function Could Allow Code E 1.0 Copyright
Want to place your software product here?
Please contact us for consideration.
Contact WareSeeker.com
- ISO Image Burner 1.1
- Microsoft Windows NT 4.0 Patch: Print Spooler Secu Update
- Microsoft Windows 98 Update: MDAC Components
- Microsoft Windows 95 Patch: Malformed Telnet Argum Update
- Microsoft Excel 2000 SR-1 Update: Macro Modificati Update
- Microsoft Security Bulletin MS03-043 828035
- EMS SQL Manager for SQL Server Lite 3.3.0.1
- Microsoft Internet Explorer 4.01 MSHTML Security P
- Microsoft Data Access Components (MDAC) 2.8 SP1
- FreeMeter 2.8.2
- NewsSeek 1.0 beta 1a
- Windows 95 Overrun Buffer Security Patch
- Windows 98 Overrun Buffer Security Patch
- Query Tool (using ODBC) 3.4 3.4
- Microsoft SQL Server 2000 (including MS SQL Server Desktop Engine 2000) Security Patch: Extended Stored Procedure Param 12-1-00
- AudioRight Burner 2.1