CVE-2011-0027

Microsoft Data Access Components (MDAC) <2.8 SP1 & WDAC 6.0 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-0027. PoCs published by Peter Vreugdenhil.

AI-analyzed exploit summary This exploit targets a heap overflow vulnerability in Microsoft Data Access Components (MDAC) via crafted XML data islands. It manipulates recordset objects to achieve arbitrary code execution by spraying the heap and bypassing ASLR.

Description

Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Peter Vreugdenhil · htmlremotewindows
https://www.exploit-db.com/exploits/15984

This exploit targets a heap overflow vulnerability in Microsoft Data Access Components (MDAC) via crafted XML data islands. It manipulates recordset objects to achieve arbitrary code execution by spraying the heap and bypassing ASLR.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Data Access Components (MDAC) in Internet Explorer
No auth needed
Prerequisites: Victim must visit a malicious webpage using Internet Explorer with vulnerable MDAC
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0075
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70444
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1024947
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12411
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42804
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45698
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA11-011A.html
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-11-002/
Vendor Advisory x_refsource_confirm
http://support.avaya.com/css/P8/documents/100124846

Scores

EPSS 0.5437
EPSS Percentile 98.9%

Details

CWE
CWE-20
Status published
Products (2)
microsoft/data_access_components 2.8 sp1 (2 CPE variants)
microsoft/windows_data_access_components 6.0
Published Jan 12, 2011
Tracked Since Feb 18, 2026