SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#176380

Microsoft Jet Database Engine fails to properly validate Access database files

Overview

A vulnerability in the Microsoft Jet database engine could allow a remote attacker to execute code of their choice on a vulnerable system.

I. Description

The Microsoft Jet Database Engine (Jet) provides data access functionality to a number of other Microsoft and many third party applications. An input validation error in the way that the Jet engine library handles the database files used by Microsoft Access (.mdb files) results in a vulnerability that could allow a remote attacker to execute code on a vulnerable system. In order to exploit this vulnerability, the attacker would need the ability to supply a specially crafted .mdb file and coax or trick a user into opening it. The malicious .mdb file could be supplied remotely by a number of methods including, but not limited to, a web page, an email message, or a shared network folder.

II. Impact

A remote, unauthenticated attacker with the ability to supply a specially crafted .mdb file could execute code of their choice on a vulnerable system. The attacker-supplied code would be executed with the same privileges as the user context of the application using the Jet Database Engine.

III. Solution

The CERT/CC is currently unaware of a practical solution to this problem.

Workarounds

Avoid opening Microsoft Access Database (.mdb) files from untrusted sources.

Systems Affected

No Information Available

References


http://marc.theaimsgroup.com/?l=bugtraq&m=111231465920199&w=2
http://www.hexview.com/docs/20050331-1.txt
http://secunia.com/advisories/14896/
http://www.securityfocus.com/bid/12960

Credit

This vulnerability was originally reported by researchers at HexView.

This document was written by Chad R Dougherty.

Other Information

Date Public03/31/2005
Date First Published10/03/2005 03:55:39 PM
Date Last Updated10/03/2005
CERT Advisory 
CVE NameCAN-2005-0944
US-CERT Technical Alerts 
Metric4.28
Document Revision10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader