Vulnerability record · CVE-2006-0003 · published 12 April 2006
CVE-2006-0003: Microsoft MDAC RDS.Dataspace ActiveX remote code execution
Microsoft · Data Access Components
The RDS.Dataspace ActiveX control shipped in Microsoft Data Access Components (MDAC) 2.7 and 2.8 contains an unspecified flaw that lets remote attackers execute arbitrary code. The record gives no root-cause detail, no affected version list beyond the MDAC 2.7/2.8 statement, and no CWE beyond 'insufficient information'. It matters because the control is reachable from a web page in Internet Explorer, giving a network attacker a code-execution path on unpatched hosts.
Description
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.
AV:N/AC:H/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution reachable from a web page with a very high EPSS score, tempered by the high access-complexity rating and the age of the affected MDAC versions.
What it is
The RDS.Dataspace ActiveX control shipped in Microsoft Data Access Components (MDAC) 2.7 and 2.8 contains an unspecified flaw that lets remote attackers execute arbitrary code. The record gives no root-cause detail, no affected version list beyond the MDAC 2.7/2.8 statement, and no CWE beyond 'insufficient information'. It matters because the control is reachable from a web page in Internet Explorer, giving a network attacker a code-execution path on unpatched hosts.
Impact
An attacker who triggers the control can run arbitrary code in the context of the logged-on user, which typically means full control of the workstation and any credentials or data it holds. No privilege escalation beyond the user's own rights is described.
Attack surface
Reached over the network (AV:N) through a malicious or compromised web page that instantiates the RDS.Dataspace ActiveX control in Internet Explorer; no authentication is required (Au:N). The CVSS vector rates access complexity as high (AC:H), implying some precondition or timing condition, but the description does not state whether any user interaction beyond visiting the page is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.825 (99.6th percentile), indicating a high modeled likelihood of exploitation activity. Reference material includes a SecurityFocus file named '0day_ie.pdf', which suggests exploit code circulated publicly, though the record does not confirm a working exploit.
What to do
- Apply Microsoft security bulletin MS06-014, which addresses this control, or the corresponding vendor update for MDAC 2.7/2.8.
- Disable or kill-bit the RDS.Dataspace ActiveX control where it is not required.
- Restrict Internet Explorer ActiveX execution and tighten the browser security zone so untrusted sites cannot instantiate the control.
- Retire or isolate hosts that still run MDAC 2.7/2.8 and cannot be patched.
Detection
- Alert on Internet Explorer or other processes loading the RDS.Dataspace ActiveX control, especially from non-corporate or untrusted origins.
- Hunt for child processes spawned by iexplore.exe, such as cmd.exe, powershell.exe or script hosts, which are abnormal for normal browsing.
- Monitor for outbound connections from browser processes to newly seen or low-reputation hosts.
- Audit endpoint and registry inventory for the RDS.Dataspace control and confirm the kill-bit or removal where it is not needed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0003 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0003), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.