Thread-topic: [SA19583] Microsoft Data Access Components RDS.Dataspace ActiveX Vulnerability
>
>
> TITLE:
> Microsoft Data Access Components RDS.Dataspace ActiveX Vulnerability
>
> SECUNIA ADVISORY ID:
> SA19583
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Highly critical
>
> IMPACT:
> System access
>
> WHERE:
> From remote
>
> OPERATING SYSTEM:
> Microsoft Windows 2000 Advanced Server
>
> Microsoft Windows 2000 Datacenter Server
>
> Microsoft Windows 2000 Professional
>
> Microsoft Windows 2000 Server
>
> Microsoft Windows XP Home Edition
>
> Microsoft Windows XP Professional
>
>
> SOFTWARE:
> Microsoft Data Access Components (MDAC) 2.x
>
>
> DESCRIPTION:
> A vulnerability has been reported in Microsoft Data Access Components
> (MDAC), which can be exploited by malicious people to compromise a
> vulnerable system.
>
> The vulnerability is caused due to an unspecified error in the
> behaviour of the RDS.Dataspace ActiveX control as it fails to ensure
> that it interacts safely with a web site.
>
> SOLUTION:
> Apply patches.
>
> Microsoft Windows XP Service Pack 1 running Microsoft Data Access
> Components 2.7 Service Pack 1:
>
> 72C-8122-4027-A117-E93227B2C79F
>
> Microsoft Windows XP Service Pack 2 running Microsoft Data Access
> Components 2.8 Service Pack 1:
>
> 72C-8122-4027-A117-E93227B2C79F
>
> Microsoft Windows XP Professional x64 Edition running Microsoft Data
> Access Components 2.8 Service Pack 2:
>
> 45D-0F01-4B79-B6B3-55279BEDB944
>
> Microsoft Windows Server 2003 running Microsoft Data Access
> Components 2.8:
>
> ED4-9B95-4593-BCB6-4BB03CA5F8F1
>
> Microsoft Windows Server 2003 Service Pack 1 running Microsoft Data
> Access Components 2.8 Service Pack 2:
>
> ED4-9B95-4593-BCB6-4BB03CA5F8F1
>
> Microsoft Windows Server 2003 for Itanium-based Systems running
> Microsoft Data Access Components 2.8:
>
> 426-E34E-4192-8A0F-35E440E948E2
>
> Microsoft Windows Server 2003 with SP1 Itanium running Microsoft Data
> Access Components 2.8 Service Pack 2:
>
> 426-E34E-4192-8A0F-35E440E948E2
>
> Microsoft Windows Server 2003 x64 Edition running Microsoft Data
> Access Components 2.8 Service Pack 2:
>
> 2C7-9819-437B-AB70-298BA62AC285
>
> Windows 2000 Service Pack 4 with Microsoft Data Access Components 2.5
> Service Pack 3 installed:
>
> CB9-1EF2-4BA1-A2F2-F87B717372FB
>
> Windows 2000 Service Pack 4 with Microsoft Data Access Components 2.7
> Service Pack 1 installed:
>
> 8B7-8417-42D8-8E73-5466C03B8C65
>
> Windows 2000 Service Pack 4 with Microsoft Data Access Components 2.8
> installed:
>
> 25D-452F-4025-8B67-41A5C840F7E2
>
> Windows 2000 Service Pack 4 with Microsoft Data Access Components 2.8
> Service Pack 1 installed:
>
> A31-959C-4E3E-8115-51DC6D441365
>
> Windows XP Service Pack 1 with Microsoft Data Access Components 2.8
> installed:
>
> 25D-452F-4025-8B67-41A5C840F7E2
>
> PROVIDED AND/OR DISCOVERED BY:
> The vendor credits:
> * Golan Yosef, Finjan.
> * Stefano Meller and Mirko Gatto, Yarix.
>
> ORIGINAL ADVISORY:
> MS06-014 (KB911562):
>
>
> OTHER REFERENCES:
> US-CERT VU#234812:
>
>
>