Vulnerability record · CVE-2002-1142 · published 29 November 2002
CVE-2002-1142: Microsoft MDAC RDS Data Stub heap buffer overflow allows remote code execution
Microsoft · Data Access Components
A heap-based buffer overflow exists in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6 and Internet Explorer 5.01 through 6.0. A remote attacker can trigger it with a malformed HTTP request to the Data Stub, potentially executing arbitrary code on the target. The flaw is remotely reachable without authentication and affects widely deployed legacy Microsoft components.
Description
Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a very high EPSS score, though it is not listed in CISA KEV and affects legacy software.
What it is
A heap-based buffer overflow exists in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6 and Internet Explorer 5.01 through 6.0. A remote attacker can trigger it with a malformed HTTP request to the Data Stub, potentially executing arbitrary code on the target. The flaw is remotely reachable without authentication and affects widely deployed legacy Microsoft components.
Impact
Successful exploitation allows a remote attacker to execute arbitrary code in the context of the vulnerable service or process. This can lead to full compromise of the affected host.
Attack surface
The vulnerability is reached over the network via a malformed HTTP request to the RDS Data Stub, as indicated by the CVSS vector AV:N/AC:L/Au:N. No authentication or user interaction is required.
Exploitation
The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS shows a 30-day probability of 0.76004 (99.5th percentile), indicating a high likelihood of exploitation activity.
What to do
- Apply the Microsoft security bulletin MS02-065 patch or the corresponding vendor update immediately.
- Disable or remove the RDS/Data Stub component where it is not required.
- Block or restrict external HTTP access to RDS endpoints at the network perimeter.
- Upgrade or retire affected MDAC 2.1–2.6 and Internet Explorer 5.01–6.0 installations.
- Monitor for and restrict unnecessary exposure of legacy Microsoft data access services.
Detection
- Inspect HTTP traffic for malformed or unusually long requests targeting RDS Data Stub endpoints.
- Monitor host and service logs for crashes or abnormal process behavior in MDAC/RDS-related components.
- Use network signatures to detect known RDS exploitation patterns against affected versions.
- Audit systems for the presence of vulnerable MDAC and Internet Explorer versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1142 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1142), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.