CVE-2012-1891

critical
Published 2012-07-10 · Modified 2026-04-29
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
9.3
VIR risk
9.8

Description

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
windows windowsnot-affected
windows windows-not-affected
windows windowsr2not-affected

Application impact

VendorProductVersionsFixed
windows microsoftdata_access_components2.8
windows microsoftwindows_data_access_components6.0

References

CWEs

CWE-119 CWE-908

Verify integrity in audit chain (admin only). AS-IS.