CVE-2002-1142
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 76%
from disclosure to weapon2837 days
Published on NVDSep 1
1st PoC+2837d
metasploitNov 2
exploitation probability
76%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/19026unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065https://exchange.xforce.ibmcloud.com/vulnerabilities/10659https://exchange.xforce.ibmcloud.com/vulnerabilities/10669https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A294https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3573http://www.cert.org/advisories/CA-2002-33.htmlhttp://www.foundstone.com/knowledge/randd-advisories-display.html?id=337http://www.kb.cert.org/vuls/id/542081http://www.securityfocus.com/bid/6214