← Vulnerability feed

Vulnerability record · CVE-2006-5559 · published 27 October 2006

CVE-2006-5559: Microsoft data access components improper input validation vulnerability

Microsoft · Data Access Components

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

9.3 CVSS 2.0 High EPSS 44% · top 1.3% CWE-20 · Improper input validation
9.3CVSS 2.0 base score
44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx
http://research.eeye.com/html/alerts/zeroday/20061027.html Patch
http://secunia.com/advisories/22452 Vendor Advisory
http://securitytracker.com/id?1017127 ExploitPatchVendor Advisory
http://www.kb.cert.org/vuls/id/589272 PatchUS Government Resource
http://www.osvdb.org/31882
http://www.securityfocus.com/bid/20704 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA07-044A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0578 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009
https://exchange.xforce.ibmcloud.com/vulnerabilities/29837
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214
http://blogs.technet.com/msrc/archive/2006/10/27/adodb-connection-poc-published.aspx
http://research.eeye.com/html/alerts/zeroday/20061027.html Patch
http://secunia.com/advisories/22452 Vendor Advisory
http://securitytracker.com/id?1017127 ExploitPatchVendor Advisory
http://www.kb.cert.org/vuls/id/589272 PatchUS Government Resource
http://www.osvdb.org/31882
http://www.securityfocus.com/bid/20704 ExploitPatch
http://www.us-cert.gov/cas/techalerts/TA07-044A.html US Government Resource
http://www.vupen.com/english/advisories/2007/0578 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-009
https://exchange.xforce.ibmcloud.com/vulnerabilities/29837
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A214

Track CVE-2006-5559 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0903Microsoft data access components memory buffer overflow vulnerabilityBuffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a mal…EPSS 37%10.0CVE-2002-1918Microsoft data access components vulnerabilityBuffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown …EPSS 16%10.0CVE-1999-1011Microsoft MDAC RDS DataFactory unsafe methods allow remote command executionThe Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe metho…EPSS 77%analysed9.8CVE-2012-1891Microsoft data access components memory buffer overflow vulnerabilityHeap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…EPSS 29%9.3CVE-2011-0026Microsoft data access components vulnerabilityInteger signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Wind…EPSS 34%9.3CVE-2011-0027Microsoft MDAC/WDAC ADO Record memory allocation flaw enables remote code executionMicrosoft Data Access Components (MDAC) 2.8 SP1/SP2 and Windows Data Access Components (WDAC) 6.0 fail to properly validate memory allocation for int…EPSS 54%analysed7.5CVE-2003-0353Microsoft data access components vulnerabilityBuffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary co…EPSS 22%7.5CVE-2002-1142Microsoft MDAC RDS Data Stub heap buffer overflow allows remote code executionA heap-based buffer overflow exists in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6 and Intern…EPSS 76%analysed

Source: NIST National Vulnerability Database (record CVE-2006-5559), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.