The Microsoft Data Access Components (MDAC) provide a number of supporting technologies for
accessing and using databases. Included among these functions is the underlying support for
the T-SQL OpenRowSet command. A security vulnerability results because the MDAC functions
underlying OpenRowSet contain an unchecked buffer.
An attacker who submitted a database query containing a specially malformed parameter within
a call to OpenRowSet could overrun the buffer, either for the purpose of causing the SQL
Server to fail or causing the SQL Server service to take actions dictated by the attacker.
Affected Software:
- Microsoft Data Access Components 2.5
- Microsoft Data Access Components 2.6
- Microsoft Data Access Components 2.7
Download locations for this patch
|