CVE-2019-0888

HIGH

Microsoft Windows ADO - ActiveX Data Objects Remote Code Execution

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-0888. PoCs published by sophoslabs.

AI-analyzed exploit summary This repository provides a link to a technical writeup by Sophos Labs detailing CVE-2019-0888, a use-after-free vulnerability in Windows ActiveX Data Objects (ADO). The writeup likely includes root cause analysis and technical details, but no functional exploit code is present in the repository itself.

Description

A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website. The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory.

Exploits (1)

nomisec WRITEUP 40 stars
by sophoslabs · poc
https://github.com/sophoslabs/CVE-2019-0888

This repository provides a link to a technical writeup by Sophos Labs detailing CVE-2019-0888, a use-after-free vulnerability in Windows ActiveX Data Objects (ADO). The writeup likely includes root cause analysis and technical details, but no functional exploit code is present in the repository itself.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Windows ActiveX Data Objects (ADO)
No auth needed
Prerequisites: Vulnerable version of Windows with ADO enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.5707
EPSS Percentile 98.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (18)
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1703
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 8 more
Published Jun 12, 2019
Tracked Since Feb 18, 2026