← Vulnerability feed

Vulnerability record · CVE-2002-1142 · published 29 November 2002

CVE-2002-1142: Microsoft MDAC RDS Data Stub heap buffer overflow allows remote code execution

Microsoft · Data Access Components

A heap-based buffer overflow exists in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6 and Internet Explorer 5.01 through 6.0. A remote attacker can trigger it with a malformed HTTP request to the Data Stub, potentially executing arbitrary code on the target. The flaw is remotely reachable without authentication and affects widely deployed legacy Microsoft components.

7.5 CVSS 2.0 High EPSS 76% · top 0.5%
7.5CVSS 2.0 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score, though it is not listed in CISA KEV and affects legacy software.

What it is

A heap-based buffer overflow exists in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6 and Internet Explorer 5.01 through 6.0. A remote attacker can trigger it with a malformed HTTP request to the Data Stub, potentially executing arbitrary code on the target. The flaw is remotely reachable without authentication and affects widely deployed legacy Microsoft components.

Impact

Successful exploitation allows a remote attacker to execute arbitrary code in the context of the vulnerable service or process. This can lead to full compromise of the affected host.

Attack surface

The vulnerability is reached over the network via a malformed HTTP request to the RDS Data Stub, as indicated by the CVSS vector AV:N/AC:L/Au:N. No authentication or user interaction is required.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS shows a 30-day probability of 0.76004 (99.5th percentile), indicating a high likelihood of exploitation activity.

What to do

  • Apply the Microsoft security bulletin MS02-065 patch or the corresponding vendor update immediately.
  • Disable or remove the RDS/Data Stub component where it is not required.
  • Block or restrict external HTTP access to RDS endpoints at the network perimeter.
  • Upgrade or retire affected MDAC 2.1–2.6 and Internet Explorer 5.01–6.0 installations.
  • Monitor for and restrict unnecessary exposure of legacy Microsoft data access services.

Detection

  • Inspect HTTP traffic for malformed or unusually long requests targeting RDS Data Stub endpoints.
  • Monitor host and service logs for crashes or abnormal process behavior in MDAC/RDS-related components.
  • Use network signatures to detect known RDS exploitation patterns against affected versions.
  • Audit systems for the presence of vulnerable MDAC and Internet Explorer versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.html
http://www.cert.org/advisories/CA-2002-33.html Third Party AdvisoryUS Government Resource
http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
http://www.kb.cert.org/vuls/id/542081 US Government Resource
http://www.securityfocus.com/bid/6214
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065
https://exchange.xforce.ibmcloud.com/vulnerabilities/10659
https://exchange.xforce.ibmcloud.com/vulnerabilities/10669
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A294
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3573
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0082.html
http://www.cert.org/advisories/CA-2002-33.html Third Party AdvisoryUS Government Resource
http://www.foundstone.com/knowledge/randd-advisories-display.html?id=337
http://www.kb.cert.org/vuls/id/542081 US Government Resource
http://www.securityfocus.com/bid/6214
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-065
https://exchange.xforce.ibmcloud.com/vulnerabilities/10659
https://exchange.xforce.ibmcloud.com/vulnerabilities/10669
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2730
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A294
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3573

Track CVE-2002-1142 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-0313Adobe Flash Player use-after-free allows remote code executionAdobe Flash Player contains a use-after-free (CWE-416) flaw reachable through unspecified vectors. It affects Flash Player before 13.0.0.269 and 14.x…KEVEPSS 95%analysed9.8CVE-2015-0311Adobe Flash Player unspecified flaw allows remote code executionCVE-2015-0311 is an unspecified vulnerability in Adobe Flash Player affecting versions through 13.0.0.262, 14.x, 15.x, and 16.x through 16.0.0.287 on…KEVEPSS 86%analysed9.8CVE-2014-1776Internet Explorer use-after-free in CMarkup::IsConnectedToPrimaryMarkupMicrosoft Internet Explorer 6 through 11 contains a use-after-free in the CMarkup::IsConnectedToPrimaryMarkup function that allows remote code execut…KEVEPSS 83%analysed8.8CVE-2021-27085Microsoft Internet Explorer remote code execution flawCVE-2021-27085 is a remote code execution vulnerability in Microsoft Internet Explorer. The record gives only a one-line description and no root-caus…KEVEPSS 5.4%analysed8.8CVE-2021-26411Microsoft Internet Explorer and Edge use-after-free memory corruptionCVE-2021-26411 is a use-after-free (CWE-416) memory corruption flaw in Microsoft Internet Explorer, with Microsoft Edge also listed as an affected pr…KEVEPSS 81%analysed8.8CVE-2019-0541Microsoft MSHTML engine input validation flaw allows remote code executionThe MSHTML engine in Microsoft Office, Internet Explorer and related viewers fails to properly validate input, allowing remote code execution. Becaus…KEVEPSS 53%analysed8.8CVE-2017-0222Internet Explorer memory corruption out-of-bounds write RCEInternet Explorer improperly accesses objects in memory, causing an out-of-bounds write (CWE-787) that can be turned into remote code execution. The …KEVEPSS 30%analysed8.8CVE-2017-0210Internet Explorer cross-domain policy bypass elevation of privilegeInternet Explorer fails to properly enforce cross-domain policies, allowing an attacker to read information from one domain and inject it into anothe…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2002-1142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.