← Back to browse · API

CVE-2012-1891

Severity
CRITICAL
CVSS
9.8
EPSS
0.29406
Risk score
49.49
CISA KEV
No
PoC
No
Published
2012-07-10
Modified
2024-10-17
First seen
2026-08-07
Aliases
EUVD-2012-1901, GHSA-9C2G-HM7X-RWG3
Products
n/a:n/a n/a
Sources
euvd EUVD-2012-1901

Description

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory, aka "ADO Cachesize Heap Overflow RCE Vulnerability."

References