Unrated severityNVD Advisory· Published Oct 27, 2006· Updated Apr 23, 2026
CVE-2006-5559
CVE-2006-5559
Description
The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.
Affected products
4cpe:2.3:a:microsoft:data_access_components:2.5:sp3:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:microsoft:data_access_components:2.5:sp3:*:*:*:*:*:*
- cpe:2.3:a:microsoft:data_access_components:2.8:sp1:*:*:*:*:*:*
- cpe:2.3:a:microsoft:data_access_components:2.8:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:data_access_components:2.7:sp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- research.eeye.com/html/alerts/zeroday/20061027.htmlnvdPatch
- www.kb.cert.org/vuls/id/589272nvdPatchUS Government Resource
- securitytracker.com/idnvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/20704nvdExploitPatch
- secunia.com/advisories/22452nvdVendor Advisory
- www.vupen.com/english/advisories/2007/0578nvdVendor Advisory
- www.us-cert.gov/cas/techalerts/TA07-044A.htmlnvdUS Government Resource
- blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspxnvd
- www.osvdb.org/31882nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29837nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214nvd
News mentions
0No linked articles in our index yet.