← Vulnerability feed

Vulnerability record · CVE-2006-0003 · published 12 April 2006

CVE-2006-0003: Microsoft MDAC RDS.Dataspace ActiveX remote code execution

Microsoft · Data Access Components

The RDS.Dataspace ActiveX control shipped in Microsoft Data Access Components (MDAC) 2.7 and 2.8 contains an unspecified flaw that lets remote attackers execute arbitrary code. The record gives no root-cause detail, no affected version list beyond the MDAC 2.7/2.8 statement, and no CWE beyond 'insufficient information'. It matters because the control is reachable from a web page in Internet Explorer, giving a network attacker a code-execution path on unpatched hosts.

5.1 CVSS 2.0 Medium EPSS 83% · top 0.3%
5.1CVSS 2.0 base score
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
58References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution reachable from a web page with a very high EPSS score, tempered by the high access-complexity rating and the age of the affected MDAC versions.

What it is

The RDS.Dataspace ActiveX control shipped in Microsoft Data Access Components (MDAC) 2.7 and 2.8 contains an unspecified flaw that lets remote attackers execute arbitrary code. The record gives no root-cause detail, no affected version list beyond the MDAC 2.7/2.8 statement, and no CWE beyond 'insufficient information'. It matters because the control is reachable from a web page in Internet Explorer, giving a network attacker a code-execution path on unpatched hosts.

Impact

An attacker who triggers the control can run arbitrary code in the context of the logged-on user, which typically means full control of the workstation and any credentials or data it holds. No privilege escalation beyond the user's own rights is described.

Attack surface

Reached over the network (AV:N) through a malicious or compromised web page that instantiates the RDS.Dataspace ActiveX control in Internet Explorer; no authentication is required (Au:N). The CVSS vector rates access complexity as high (AC:H), implying some precondition or timing condition, but the description does not state whether any user interaction beyond visiting the page is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.825 (99.6th percentile), indicating a high modeled likelihood of exploitation activity. Reference material includes a SecurityFocus file named '0day_ie.pdf', which suggests exploit code circulated publicly, though the record does not confirm a working exploit.

What to do

  • Apply Microsoft security bulletin MS06-014, which addresses this control, or the corresponding vendor update for MDAC 2.7/2.8.
  • Disable or kill-bit the RDS.Dataspace ActiveX control where it is not required.
  • Restrict Internet Explorer ActiveX execution and tighten the browser security zone so untrusted sites cannot instantiate the control.
  • Retire or isolate hosts that still run MDAC 2.7/2.8 and cannot be patched.

Detection

  • Alert on Internet Explorer or other processes loading the RDS.Dataspace ActiveX control, especially from non-corporate or untrusted origins.
  • Hunt for child processes spawned by iexplore.exe, such as cmd.exe, powershell.exe or script hosts, which are abnormal for normal browsing.
  • Monitor for outbound connections from browser processes to newly seen or low-reputation hosts.
  • Audit endpoint and registry inventory for the RDS.Dataspace control and confirm the kill-bit or removal where it is not needed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/19583 Vendor Advisory
http://secunia.com/advisories/20719
http://securitytracker.com/id?1015894
http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html
http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html
http://www.kb.cert.org/vuls/id/234812 Third Party AdvisoryUS Government Resource
http://www.osvdb.org/24517
http://www.securityfocus.com/archive/1/475104/100/100/threaded
http://www.securityfocus.com/archive/1/475108/100/100/threaded
http://www.securityfocus.com/archive/1/475118/100/100/threaded
http://www.securityfocus.com/archive/1/475490/100/100/threaded
http://www.securityfocus.com/archive/1/487216/100/200/threaded
http://www.securityfocus.com/archive/1/487219/100/200/threaded
http://www.securityfocus.com/bid/17462
http://www.securityfocus.com/bid/20797
http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf
http://www.us-cert.gov/cas/techalerts/TA06-101A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2006/1319
http://www.vupen.com/english/advisories/2006/2452
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-014
https://exchange.xforce.ibmcloud.com/vulnerabilities/25006
https://exchange.xforce.ibmcloud.com/vulnerabilities/29915
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1204
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1323
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1511
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1742
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1778
https://www.exploit-db.com/exploits/2052
https://www.exploit-db.com/exploits/2164
http://secunia.com/advisories/19583 Vendor Advisory
http://secunia.com/advisories/20719
http://securitytracker.com/id?1015894
http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/01-e.html
http://www.hitachi-support.com/security_e/vuls_e/HS06-013_e/index-e.html
http://www.kb.cert.org/vuls/id/234812 Third Party AdvisoryUS Government Resource
http://www.osvdb.org/24517
http://www.securityfocus.com/archive/1/475104/100/100/threaded
http://www.securityfocus.com/archive/1/475108/100/100/threaded
http://www.securityfocus.com/archive/1/475118/100/100/threaded
http://www.securityfocus.com/archive/1/475490/100/100/threaded

Track CVE-2006-0003 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0903Microsoft data access components memory buffer overflow vulnerabilityBuffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a mal…EPSS 37%10.0CVE-2002-1918Microsoft data access components vulnerabilityBuffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown …EPSS 16%10.0CVE-1999-1011Microsoft MDAC RDS DataFactory unsafe methods allow remote command executionThe Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe metho…EPSS 77%analysed9.8CVE-2012-1891Microsoft data access components memory buffer overflow vulnerabilityHeap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…EPSS 29%9.3CVE-2011-0026Microsoft data access components vulnerabilityInteger signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Wind…EPSS 34%9.3CVE-2011-0027Microsoft MDAC/WDAC ADO Record memory allocation flaw enables remote code executionMicrosoft Data Access Components (MDAC) 2.8 SP1/SP2 and Windows Data Access Components (WDAC) 6.0 fail to properly validate memory allocation for int…EPSS 54%analysed9.3CVE-2006-5559Microsoft data access components improper input validation vulnerabilityThe Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data …EPSS 44%7.5CVE-2003-0353Microsoft data access components vulnerabilityBuffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary co…EPSS 22%

Source: NIST National Vulnerability Database (record CVE-2006-0003), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.