← Vulnerability feed

Vulnerability record · CVE-2011-0027 · published 12 January 2011

CVE-2011-0027: Microsoft MDAC/WDAC ADO Record memory allocation flaw enables remote code execution

Microsoft · Data Access Components

Microsoft Data Access Components (MDAC) 2.8 SP1/SP2 and Windows Data Access Components (WDAC) 6.0 fail to properly validate memory allocation for internal data structures, allowing an integer wrap and buffer overflow, possibly triggered by a large CacheSize property. This is the ADO Record Memory Vulnerability addressed in MS11-002. Because it can lead to arbitrary code execution, it matters for any system exposing the affected data access stack to untrusted input.

9.3 CVSS 2.0 High EPSS 54% · top 1.0% CWE-20 · Improper input validation
9.3CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory allocation for internal data structures, which allows remote attackers to execute arbitrary code, possibly via a large CacheSize property that triggers an integer wrap and a buffer overflow, aka "ADO Record Memory Vulnerability." NOTE: this might be a duplicate of CVE-2010-1117 or CVE-2010-1118.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated remote code execution with complete impact and has a very high EPSS score, though it is not in CISA KEV and affects legacy components.

What it is

Microsoft Data Access Components (MDAC) 2.8 SP1/SP2 and Windows Data Access Components (WDAC) 6.0 fail to properly validate memory allocation for internal data structures, allowing an integer wrap and buffer overflow, possibly triggered by a large CacheSize property. This is the ADO Record Memory Vulnerability addressed in MS11-002. Because it can lead to arbitrary code execution, it matters for any system exposing the affected data access stack to untrusted input.

Impact

A remote attacker can execute arbitrary code in the context of the vulnerable process, giving full control of confidentiality, integrity and availability on the affected host. The CVSS 2.0 vector rates complete impact across all three categories.

Attack surface

The CVSS 2.0 vector AV:N/AC:M/Au:N indicates the flaw is reachable over the network with no authentication required, though some conditions must be met for a successful attack. The description points to a crafted CacheSize property as the likely trigger, so the attack surface is any path where untrusted data reaches the ADO Record handling code.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at 0.54372 (99th percentile), indicating elevated likelihood of exploitation activity. References include a Pwn2Own heap overflow writeup and a Zero Day Initiative advisory, which show public technical detail exists, but the record does not confirm active exploitation in the wild.

What to do

  • Apply the Microsoft MS11-002 security update to affected MDAC 2.8 SP1/SP2 and WDAC 6.0 installations as the primary fix.
  • Inventory systems still running MDAC 2.8 or WDAC 6.0 and prioritize them for patching, since these are legacy components.
  • Restrict or block untrusted input paths that can reach ADO Record handling code, such as untrusted web content or documents processed by applications using these components.
  • Where patching is not immediately possible, isolate affected systems and limit network exposure of services that consume untrusted data through the data access stack.

Detection

  • Monitor for crashes or abnormal process terminations in applications that use MDAC/WDAC, which may indicate exploitation attempts against this memory allocation flaw.
  • Hunt for processes loading MDAC/WDAC related DLLs that subsequently spawn unexpected child processes or make unusual network connections.
  • Review endpoint and application logs for repeated malformed input or oversized property values reaching ADO Record handling code.
  • Track patch status of MDAC 2.8 SP1/SP2 and WDAC 6.0 across the estate to identify unpatched exposure.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-0027 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2003-0903Microsoft data access components memory buffer overflow vulnerabilityBuffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a mal…EPSS 37%10.0CVE-2002-1918Microsoft data access components vulnerabilityBuffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown …EPSS 16%10.0CVE-1999-1011Microsoft MDAC RDS DataFactory unsafe methods allow remote command executionThe Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC), as shipped with IIS 3.x and 4.x, exposes unsafe metho…EPSS 77%analysed9.8CVE-2012-1891Microsoft data access components memory buffer overflow vulnerabilityHeap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote att…EPSS 29%9.3CVE-2011-0026Microsoft data access components vulnerabilityInteger signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Wind…EPSS 34%9.3CVE-2006-5559Microsoft data access components improper input validation vulnerabilityThe Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data …EPSS 44%7.5CVE-2003-0353Microsoft data access components vulnerabilityBuffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary co…EPSS 22%7.5CVE-2002-1142Microsoft MDAC RDS Data Stub heap buffer overflow allows remote code executionA heap-based buffer overflow exists in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6 and Intern…EPSS 76%analysed

Source: NIST National Vulnerability Database (record CVE-2011-0027), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.